Microsoft patched a maximum-severity vulnerability in its M365 Copilot AI platform last Tuesday. Researchers who reported the flaw demonstrated a proof-of-concept exploit that could steal two-factor authentication codes and other sensitive data from emails accessible to Copilot.
The root cause is that large language models cannot distinguish user instructions from malicious commands embedded in third-party content. Attackers bypass guardrails using markup language or HTML tags to exfiltrate data to their own servers.
Comments