Microsoft Copilot Tricked Into Revealing the Secret Input That Enabled Its Own Exploitation

Security researchers at Varonis exploited Microsoft 365 Copilot for enterprise by tricking the AI into revealing an undocumented prompt parameter that bypassed its user-consent safeguards. This parameter allowed an attack that could exfiltrate user passwords and sensitive data when a victim merely clicked a link. Instead of using reverse engineering, the researchers elicited the vulnerability details directly from Copilot through carefully crafted questions about its guardrails.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleStanford Study: AI Impact Falls Heaviest on Entry-Level Workers
Start typing to search