Microsoft Copilot reveals secret input that allowed it to be hacked

Summary

Microsoft Copilot was found to have a vulnerability that allowed hackers to steal user passwords. This was achieved by a secret parameter that, when exploited through a specially crafted link, could exfiltrate credentials.

IFF Assessment

FOE

This finding represents a significant security flaw in a widely used AI assistant, enabling potential credential theft and posing a direct threat to users.

Defender Context

This incident highlights the ongoing risks associated with integrating AI assistants into workflows, particularly regarding data privacy and credential security. Defenders should be vigilant about potential vulnerabilities in AI tools and educate users on the dangers of clicking suspicious links, even when originating from trusted applications.

Read Full Story →