💻
💻 Technology

Researchers tricked Microsoft 365 Copilot into leaking user passwords

Security researchers at Varonis found a critical vulnerability in Microsoft 365 Copilot Enterprise that allowed attackers to exfiltrate user passwords and sensitive data with no more than a single click from the victim. Unusually, the researchers discovered the exploit method by simply asking Copilot itself, which readily provided the information. The attack bypassed Copilot's built-in safeguards requiring explicit user consent for sensitive actions.

Comments

No comments yet