AI Tools & Products
6d ago
Researchers exploit vulnerability in Microsoft 365 Copilot to access sensitive data
Aug 18, 2026
AI Summary
A security firm has demonstrated a vulnerability in Microsoft 365 Copilot that allowed them to extract user passwords and sensitive information without user consent. By questioning the AI about its safety mechanisms, they uncovered a hidden prompt parameter that bypassed necessary user confirmations.

- Researchers from Varonis identified a vulnerability in Microsoft 365 Copilot Enterprise that enabled unauthorized access to user data.
- The exploit was achieved by querying Copilot about its safety protocols, leading to the discovery of an undocumented prompt parameter.
- Normally, Copilot requires explicit user consent for sensitive actions, but the researchers found a way to circumvent this requirement through their questioning strategy.
microsoftcopilothackingsecuritypasswords