Critical Microsoft Copilot Vulnerability Exposed Users' Two-Factor Authentication Codes

Microsoft patched a maximum-severity vulnerability in its M365 Copilot AI platform last Tuesday after researchers demonstrated a proof-of-concept exploit that could steal two-factor authentication codes and other sensitive data from accessible emails. The root cause is that large language models cannot distinguish between legitimate user instructions and malicious commands hidden in third-party content, making them inherently gullible. To bypass Copilot's guardrails against data exfiltration, attackers used markup language or HTML tags to embed sensitive data in web requests that were sent to an attacker-controlled server, where the information was captured.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleWeb Scraper Declares 'Google and Reddit Do Not Own the Internet' After Court Victory
Start typing to search