Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Microsoft Copilot reveals secret input that allowed it to be hacked

Varonis said the flaw let crafted links trigger prompt injection and data theft from connected services, including Gmail and Google Drive, without user approval.

Summary by Ars Technica
It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Co…

4 Articles

Microsoft Copilot for Word was supposed to help users create and edit documents, but researcher Håkon Måløy discovered a way to exploit this feature against users. The problem involves a prompt injection attack, in which malicious commands are hidden within a seemingly ordinary document. Such a file can become a vector for the attack, transmitting hidden instructions to subsequent documents. Therefore, this isn't a classic computer virus. This t…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Register broke the news in London, United Kingdom on Tuesday, August 18, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal