Critical Copilot vulnerability allowed hackers to seal 2FA code from users
Security researchers identified a vulnerability in Microsoft Copilot that could allow attackers to bypass privacy safeguards and steal sensitive user information, including two-factor authentication codes. By manipulating search queries, hackers can exfiltrate data from private internal documents processed by the AI. This flaw highlights ongoing systemic security challenges in how large language models handle and retrieve protected user data during automated interactions.
Covered by 1 source
- AArs Technica↗Dan GoodinJun 16