Security researchers at Varonis exploited Microsoft 365 Copilot for enterprise by prompting the AI to reveal an undocumented parameter that bypassed its user-consent safeguards. Through a series of questions about its guardrails, Copilot disclosed the hidden input, allowing the researchers to craft an exploit that could exfiltrate user data with just a single click.
The attack required no traditional reverse engineering, as the AI assistant itself provided the key vulnerability details. The discovery highlights how AI systems can inadvertently leak sensitive internal mechanisms.
Comments