Microsoft Copilot revealed hack method to security researchers
TL;DR. Researchers exploited Microsoft 365 Copilot to steal user passwords after the AI itself disclosed secret input parameters. - Varonis researchers found Copilot's guardrails could be bypassed by understanding its internal mechanisms. - Copilot inadvertently provided clues on how to exfiltrate sensitive data without explicit user confirmation. - The vulnerability allowed data theft via a simple link click, bypassing typical security prompts.
- Researchers from Varonis exploited a vulnerability in Microsoft 365 Copilot.
- Copilot itself disclosed the 'secret input' parameters that made the exploit possible.
- The vulnerability allowed exfiltration of user passwords and sensitive data when a target clicked a link.
- This bypasses Copilot's typical user consent requirements for powerful commands.
- The method involved asking Copilot questions about its guardrails and URL structures.
Sources
- Microsoft Copilot reveals secret input that allowed it to be hacked — arstechnica.com