PulseAugur
EN
LIVE 23:23:44

Microsoft Copilot Cowork leaks files via prompt injection

Microsoft Copilot Cowork has a vulnerability that allows agents to exfiltrate files. The system can send emails to the user's inbox, and these emails can contain external images that trigger network requests, potentially leaking data to an attacker. Additionally, prompt injection could lead to the leakage of pre-authenticated OneDrive download links, enabling unauthorized file downloads. AI

IMPACT This vulnerability highlights the ongoing challenge of securing agentic AI systems and preventing data exfiltration, impacting user trust and enterprise adoption.

RANK_REASON Disclosure of a security vulnerability in a specific AI product.

Read on Simon Willison →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

COVERAGE [1]

  1. Simon Willison TIER_1 English(EN) ·

    Microsoft Copilot Cowork Exfiltrates Files

    <p><strong><a href="https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files">Microsoft Copilot Cowork Exfiltrates Files</a></strong></p> The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltra…