← Back to Model Beat
Products·Jun 16·all news from June 16, 2026

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

Security researchers identified a vulnerability in Microsoft Copilot that could allow attackers to bypass privacy safeguards and steal sensitive user information, including two-factor authentication codes. By manipulating search queries, hackers can exfiltrate data from private internal documents processed by the AI. This flaw highlights ongoing systemic security challenges in how large language models handle and retrieve protected user data during automated interactions.

Covered by 1 source

Related stories

ProductsNew usage analytics and updated spend controls for enterprisesJun 18 · 2 sourcesProductsAdobe adds AI agents to Photoshop, Premiere, and more Creative Cloud appsJun 18ProductsMeta’s new ‘AI Mode’ on Facebook pulls from public info across its platformsJun 15 · 3 sourcesProductsFirst, do NOHARM: towards clinically safe large language modelsJun 16 · 2 sources