Copirate 365: Researcher Demos Data Exfil in Microsoft Copilot via Font Loading
wunderwuzzi23 · x · 2026-09-05
Security researcher wunderwuzzi released the talk "Copirate 365: Plundering in the depths of Microsoft Copilot", a survey of Microsoft Copilot security weaknesses with live demos:
- A brief history of AI data exfiltration exploits over the past 3+ years
- Data exfil across M365 Copilots via font loading, encoding stolen data in external font requests
- Memory writes + "SpAIware": planting persistent instructions for spyware-like behavior
- Consumer Copilot exploits
The full talk is available on YouTube.
More from Safety
- Where AI Collides with PCI DSS: The Compliance Lines Firms Overlook — TechNadu · 2026-09-05
- AI Quietly Expands PCI DSS Scope Through Prompts, Agents and Vector DBs — TechNadu · 2026-09-05
- DPRK-linked hackers trojanize 14 Mac apps including Sketch and Bartender — TechNadu · 2026-09-05
- Boaz Barak: alignment improved but gap vs needed capability remains wide — i_dg23 · 2026-09-05
- OpenAI backs California SB 1119 on teen chatbot safety, launches ChatGPT for Teens — emmanuelvivier · 2026-09-05
- US and China reportedly prepping first bilateral AI safety dialogue in mid-September — emmanuelvivier · 2026-09-05