New Microsoft 365 Copilot flaw: how hackers can plunder your data with a 'single click'
Summary
Varonis researchers identified a critical flaw in Microsoft 365 Copilot Enterprise that could let attackers steal sensitive enterprise data with a single click. The attack chain exploits hidden instructions in a link, Copilot’s search behavior across Outlook, SharePoint, and Teams, and a Bing-based bypass to leak emails, authentication codes, and files. Microsoft had already placed some guardrails around Copilot output, but the researchers showed how the chain still worked before the issue was patched server-side. The disclosure highlights ongoing security risks in AI assistants that have deep access to corporate content.
Classifications
industries
HealthTech
applications
Accounting and Taxes
AskAI Classifications
Labels
Cybersecurity Software
Data Security
SaaS