Microsoft has patched a critical vulnerability in its M365 Copilot AI platform that allowed attackers to retrieve two-factor authentication codes and other sensitive data from emails. The flaw, reported by security researchers, stems from AI bots' inability to distinguish between user commands and malicious instructions embedded in third-party content. Attackers bypassed existing guardrails by using markup language or HTML tags to exfiltrate the stolen data to their own servers.
Microsoft Patches Critical Copilot Vulnerability That Exposed 2FA Codes
vidgetc
Tech, gaming & AI news — always at hand
Google Play · Soon
App Store · Soon
Comments