Researchers tricked Microsoft 365 Copilot into leaking user passwords
Security researchers at Varonis found a critical vulnerability in Microsoft 365 Copilot Enterprise that allowed attackers to exfiltrate user passwords and sensitive data with no more than a single click from the victim. Unusually, the researchers discovered the exploit method by simply asking Copilot itself, which readily provided the information. The attack bypassed Copilot's built-in safeguards requiring explicit user consent for sensitive actions.
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!