Microsoft patched a critical vulnerability in its M365 Copilot AI platform last Tuesday. Researchers who discovered the flaw revealed a proof-of-concept exploit that could retrieve two-factor authentication codes and other sensitive data from emails accessible to Copilot. The vulnerability stems from AI bots' inability to distinguish between user commands and malicious instructions hidden in third-party content, which can bypass guardrails using markup language or HTML tags to exfiltrate data to an attacker's server.
Microsoft Patches Critical Copilot Vulnerability That Could Expose 2FA Codes
vidgetc
Tech, gaming & AI news — always at hand
Google Play · Soon
App Store · Soon
Comments