New Microsoft 365 Copilot flaw: how hackers can plunder your data with a 'single click'

General News

Summary

Varonis researchers identified a critical flaw in Microsoft 365 Copilot Enterprise that could let attackers steal sensitive enterprise data with a single click. The attack chain exploits hidden instructions in a link, Copilot’s search behavior across Outlook, SharePoint, and Teams, and a Bing-based bypass to leak emails, authentication codes, and files. Microsoft had already placed some guardrails around Copilot output, but the researchers showed how the chain still worked before the issue was patched server-side. The disclosure highlights ongoing security risks in AI assistants that have deep access to corporate content.

Classifications

industries
HealthTech
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software Data Security SaaS

Linked Companies

Varonis
$250M to $500M
WhatsApp
$100M to $250M
Google LLC
$100M to $250M
Microsoft
$1B+