At BlueHat Asia, researcher shows SQL Copilot prompt injection breaks read-only assumptions

wunderwuzzi23 · x · 2026-09-18

Security researcher Johann Rehberger presented at Microsoft's BlueHat Asia on AI assistants inheriting user privileges: SQL Copilot in SQL Server Management Studio becomes a powerful attack target when connected to highly privileged accounts. Live demos showed how "read-only" assumptions break down and prompt injection can steer AI behavior. Key message: security boundaries matter as much as model instructions.

Original post →

More from Safety

Safety channel →