Critical Copilot vulnerability allowed hackers to seal 2FA code from users

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

Last week, Microsoft addressed a significant security flaw in its M365 Copilot AI platform, labeling it as critically severe. On Monday, researchers unveiled how they managed to exploit this vulnerability, demonstrating that it could be used to extract two-factor authentication (2FA) codes along with other sensitive information from emails accessed by Copilot. The challenge lies in the inherent limitations of AI systems like Copilot, which struggle to differentiate between legitimate user commands and malicious instructions embedded within third-party content. This inability to effectively secure this boundary has left Microsoft and other large language model (LLM) developers scrambling to establish complex, makeshift safeguards to mitigate potential risks. One of the protective measures implemented in Copilot, and many other LLMs, is designed to prevent the submission of web forms or sending emails that could lead to data exfiltration. However, attackers have found ways to bypass these restrictions using markup language. This language allows users to format text without relying on HTML tags, enabling hackers to hide sensitive information within HTML tags like <img> and <form>. When exploited, these tactics can trigger web requests that transmit the captured data to the attacker's server, where it is recorded. Microsoft has implemented various guardrails, including encapsulating Copilot outputs in <code> blocks to ensure the browser interprets them as plain text and limiting access to unapproved websites. Nonetheless, a security firm named Varonis successfully crafted an exploit chain that circumvented these defenses. Their approach, identified as Parameter-to-Prompt Injection, leverages the 'q' parameter in a URL, which identifies included queries. This technique closely resembles prompt injection, except that the harmful command is embedded within the query parameter instead of being hidden in an email or untrusted content.

Sources : Ars Technica

Published On : Jun 16, 2026, 11:25

Computing
South Korea's Stock Market: The New Pulse of Global AI Investments

The stock market in South Korea is rapidly emerging as a critical indicator for the global AI industry, with its pronoun...

Business Insider | Jul 21, 2026, 08:25
South Korea's Stock Market: The New Pulse of Global AI Investments
AI
Kimi K3 Ignites Debate on China's AI Landscape Amidst Global Competition

The recent unveiling of Moonshot AI's Kimi K3 model has set the Chinese internet abuzz with conversations and comparison...

Business Insider | Jul 21, 2026, 09:30
Kimi K3 Ignites Debate on China's AI Landscape Amidst Global Competition
AI
Anthropic Secures Unprecedented $1.5 Billion Settlement in Copyright Case

Anthropic has reached a monumental $1.5 billion settlement with a group of authors who accused the company of utilizing ...

Business Today | Jul 21, 2026, 13:10
Anthropic Secures Unprecedented $1.5 Billion Settlement in Copyright Case
Mobile
Oppo Raises Prices of K14 Series and A6s in India Amid Component Shortages

Oppo has announced a price increase for its budget-friendly K series smartphones, specifically the Oppo K14 and K14x mod...

Business Today | Jul 21, 2026, 09:35
Oppo Raises Prices of K14 Series and A6s in India Amid Component Shortages
Startups
OpenAI's Ambitious Advertising Aspirations: Can ChatGPT Compete with Giants?

OpenAI is navigating a challenging landscape as it seeks to carve out a niche in the advertising realm through its popul...

Business Insider | Jul 21, 2026, 09:10
OpenAI's Ambitious Advertising Aspirations: Can ChatGPT Compete with Giants?
View All News