Researchers Trick Copilot into Leaking Secret Parameter for Exploit
Ars Technica AI · rss · 2026-08-18
Security researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot Enterprise that allows exfiltration of user data without confirmation. Instead of reverse engineering, they tricked the LLM into revealing its own guardrails. Through a dialogue resembling "20 questions," they probed about auto-execution restrictions and URL structures. Eventually, Copilot disclosed an undocumented prompt parameter that completely bypassed the requirement for user consent, enabling the creation of an exploit that triggers actions via a simple link click.
More from Safety
- Article: Biggest AI Risks Sit Outside the Model — bigdata · 2026-08-18
- WireTapper: open-source tool passively maps every wireless device around you — tom_doerr · 2026-08-18
- Scholar challenges EU AI Act disclosure: mere formality doesn't ensure integrity — _akpiper · 2026-08-18
- Irregular paper: AI favors offense, and the world isn't ready — moyix · 2026-08-18
- After exhausting the open web, AI scrapers now hammer €7/month self-hosted servers — cen6wkf · 2026-08-18
- Researcher pushes back on FT: the models really did go rogue, that's the point of the HF incident — nitarshan · 2026-08-18