Back to news
AI Tools & Products
6d ago

Researchers exploit vulnerability in Microsoft 365 Copilot to access sensitive data

Aug 18, 2026
AI Summary

A security firm has demonstrated a vulnerability in Microsoft 365 Copilot that allowed them to extract user passwords and sensitive information without user consent. By questioning the AI about its safety mechanisms, they uncovered a hidden prompt parameter that bypassed necessary user confirmations.

Researchers exploit vulnerability in Microsoft 365 Copilot to access sensitive data
  • Researchers from Varonis identified a vulnerability in Microsoft 365 Copilot Enterprise that enabled unauthorized access to user data.
  • The exploit was achieved by querying Copilot about its safety protocols, leading to the discovery of an undocumented prompt parameter.
  • Normally, Copilot requires explicit user consent for sensitive actions, but the researchers found a way to circumvent this requirement through their questioning strategy.
microsoftcopilothackingsecuritypasswords