Researchers at security firm Varonis exploited Microsoft 365 Copilot to exfiltrate user data through a single link click. To build the attack, they asked Copilot directly about its safety mechanisms instead of reverse engineering the system.
The AI assistant gradually revealed an undocumented prompt parameter that completely bypassed the need for user confirmation. This allowed the researchers to access sensitive data without any user gesture.
Comments