Critical Microsoft Copilot Vulnerability Could Let Attackers Steal 2FA Codes

Microsoft patched a critical vulnerability in its M365 Copilot AI platform last Tuesday. Researchers who discovered the flaw showed how their proof-of-concept exploit could retrieve two-factor authentication codes and other sensitive data from emails Copilot could access.

The underlying issue is that AI chatbots cannot distinguish user instructions from those embedded in third-party content, making them susceptible to data exfiltration. Attackers bypassed guardrails by using markup language or HTML tags to send stolen data to their own servers.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleWeb Scraper Declares 'Google and Reddit Do Not Own the Internet' After Court Victory
Start typing to search