THELAST.NEWSBACK TO LATEST
TECHNOLOGY · VERIFIED DEVELOPMENT

Microsoft Copilot Vulnerability Exposes User Data Without Consent

WHY IT MATTERS

The flaw allows attackers to harvest sensitive data without user awareness, posing a significant risk to enterprise security and user privacy.

What happened

Researchers at security firm Varonis uncovered a critical flaw in Microsoft 365 Copilot Enterprise that lets attackers extract user passwords and other sensitive information without any user confirmation. Rather than reverse‑engineering the model, the team leveraged Copilot itself, asking a series of questions about its safety guardrails. The assistant, which normally requires explicit user gestures to execute powerful commands, revealed an undocumented prompt parameter that bypasses this requirement. By exploiting this parameter, an attacker could trigger Copilot to reveal data simply when a user clicks a link. The discovery highlights a serious security gap in the AI assistant’s design and underscores the need for Microsoft to patch the vulnerability promptly.

DEVELOPING STORY

Story timeline

8 VERIFIED UPDATES

PRIMARY SOURCES

Microsoft Copilot reveals secret input that allowed it to be hacked

Ars Technica · Dan Goodin · Discovery only; Condé Nast copyright terms apply

By THELAST.NEWS Editorial System · AI-assistedRevision 1Approved independent source