Microsoft Copilot reveals secret input that allowed it to be hacked
AI Generated Image

Microsoft Copilot reveals secret input that allowed it to be hacked

Ars Technica general

Key Points:

  • Researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot Enterprise that allowed user passwords and sensitive data to be exfiltrated without user consent by exploiting an undocumented URL parameter (?autorun=1) that bypassed security guardrails.
  • The exploit involved embedding malicious prompts in URLs that, when clicked, triggered Copilot to automatically execute commands such as searching inboxes for emails and credentials, then sending this data to attacker-controlled servers covertly.
  • Microsoft mitigated the vulnerability in February by disabling the ability to inject text into the chatbot input via URLs, requiring manual user interaction; more comprehensive fixes were released recently.
  • Varonis also demonstrated a separate attack that poisoned Copilot’s permanent memory store through prompt injection in web pages, potentially allowing attackers to bias responses or execute malicious actions persistently across sessions.
  • These findings highlight the limitations of reactive AI guardrails and underscore the need for users to remain cautious about clicking suspicious links and limiting app integrations with AI assistants to reduce security risks.

Trending Business

Trending Technology

Trending Health