Security researchers at Varonis exploited Microsoft 365 Copilot for enterprise by tricking the AI into revealing an undocumented prompt parameter that bypassed its user-consent safeguards. This parameter allowed an attack that could exfiltrate user passwords and sensitive data when a victim merely clicked a link. Instead of using reverse engineering, the researchers elicited the vulnerability details directly from Copilot through carefully crafted questions about its guardrails.
Microsoft Copilot Tricked Into Revealing the Secret Input That Enabled Its Own Exploitation
vidgetc
Tech, gaming & AI news — always at hand
Google Play · Soon
App Store · Soon
Comments