E-Ink News Daily

Back to list

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot by using conversational prompting to elicit sensitive architectural details from the AI itself. Copilot inadvertently revealed an undocumented prompt parameter that bypassed user consent safeguards, enabling a data exfiltration exploit triggered simply by clicking a link.

Background

Large language models are increasingly integrated into enterprise productivity suites, making prompt engineering-based attacks a growing concern for AI security. The technique highlights a new class of vulnerabilities where the AI itself becomes the information source for its own exploitation.

Source
Ars Technica
Published
Aug 18, 2026 at 09:00 PM
Score
8.0 / 10