Microsoft Copilot Leak Reveals Hack to Bypass User Confirmation

luisdans · x · 2026-08-18

Researchers found a critical vulnerability in Microsoft 365 Copilot Enterprise. By probing the model about its guardrails, they elicited a secret parameter that bypasses user confirmation. This allowed crafting malicious links to steal passwords and sensitive data solely via a click.

Original post →

More from Models

Models channel →