Microsoft Patches Critical Copilot Flaw Exposing Two-Factor Codes

Microsoft patched a maximum-severity vulnerability in its M365 Copilot AI platform last Tuesday. Researchers who reported the flaw demonstrated a proof-of-concept exploit that could steal two-factor authentication codes and other sensitive data from emails accessible to Copilot.

The root cause is that large language models cannot distinguish user instructions from malicious commands embedded in third-party content. Attackers bypass guardrails using markup language or HTML tags to exfiltrate data to their own servers.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleWeb Scraper Declares 'Google and Reddit Do Not Own the Internet' After Court Victory
Start typing to search