Microsoft patched a critical vulnerability in its AI platform M365 Copilot after researchers revealed their proof-of-concept exploit could steal 2FA codes and sensitive data. The vulnerability stemmed from the inability of LLMs to distinguish between user instructions and third-party content they are processing, leaving them vulnerable to malicious requests for data extraction. This has led to developers creating complex workarounds like using markup language or embedding sensitive data in HTML tags to bypass basic security measures, ultimately exposing data to attackers.
M365 Copilot Vulnerability Allows Hackers to Steal 2FA Codes
vidgetc
Tech, gaming & AI news — always at hand
Google Play · Soon
App Store · Soon
Comments