Microsoft Copilot Exposes Its Own Security Flaw After Being Questioned by Researchers

Researchers at security firm Varonis exploited Microsoft 365 Copilot to exfiltrate user data through a single link click. To build the attack, they asked Copilot directly about its safety mechanisms instead of reverse engineering the system.

The AI assistant gradually revealed an undocumented prompt parameter that completely bypassed the need for user confirmation. This allowed the researchers to access sensitive data without any user gesture.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers
Start typing to search