CybersecurityDev3 min reading time

Microsoft Copilot reveals secret input that allowed it to be hacked

Covered by 2 sources
Read full post
Security researchers discovered an undocumented URL parameter in Microsoft Copilot that allows attackers to inject prompts and exfiltrate sensitive data like email addresses and passwords without user consent. This vulnerability enables crafted URLs to execute commands automatically, leaking information to attacker-controlled servers.

Covered by 2 sources


More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources
Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch