Microsoft Copilot Leak Reveals Hack to Bypass User Confirmation
luisdans · x · 2026-08-18
Researchers found a critical vulnerability in Microsoft 365 Copilot Enterprise. By probing the model about its guardrails, they elicited a secret parameter that bypasses user confirmation. This allowed crafting malicious links to steal passwords and sensitive data solely via a click.
More from Models
- Anthropic reportedly testing Fable 5 successor on subset of Claude accounts — kimmonismus · 2026-08-18
- Qwen 4 expected in September; Qwen 3.8 praised for performance — Usual_Maximum7673 · 2026-08-18
- AI research tool Fable surfaces an offline-only econ JMP linking Lindahl and Kantian equilibria — soumitrashukla9 · 2026-08-18
- Is Ling 3 Tiny underrated? Benchmarks suggest it beats Qwen3.5 9B — Hot_Example_4456 · 2026-08-18
- Grok 4.6 can reportedly reverse engineer any modern web app — jasonkneen · 2026-08-18
- User surprised by how good GPT Luna is: smart and pleasant to use — oyacaro · 2026-08-18