Microsoft Copilot revealed hack method to security researchers

TL;DR. Researchers exploited Microsoft 365 Copilot to steal user passwords after the AI itself disclosed secret input parameters. - Varonis researchers found Copilot's guardrails could be bypassed by understanding its internal mechanisms. - Copilot inadvertently provided clues on how to exfiltrate sensitive data without explicit user confirmation. - The vulnerability allowed data theft via a simple link click, bypassing typical security prompts.

Sources

Back to QLANKR News