← Back to Model Beat
Products·Aug 18·all news from August 18, 2026

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers discovered a hidden parameter in Microsoft Copilot that could be manipulated to execute unauthorized actions, including the potential theft of user credentials. By embedding a malicious link that exploited this vulnerability, an attacker could force the assistant to perform unintended tasks when a user interacted with the prompt. This finding highlights ongoing security challenges in mitigating prompt injection and interface vulnerabilities within large language model integrations.

Covered by 1 source

Related stories

ProductsTerence Tao says AI could trigger math's biggest crisis since GödelAug 20 · 2 sourcesProductsOffering Zero Data Retention for frontier modelsAug 19 · 2 sourcesProductsChatGPT Can Now Control iMessage, Potentially Raising Apple Privacy ConcernsAug 20 · 2 sourcesProductsAttackers are using AI to build exploits for industrial control systems, U.S. agencies warnAug 19 · 3 sources