PulseAugur
EN
LIVE 08:57:03

Microsoft patches critical Copilot vulnerability allowing 2FA code theft

Microsoft has patched a critical vulnerability in its M365 Copilot AI platform that allowed hackers to steal two-factor authentication (2FA) codes and other sensitive data. Researchers demonstrated an exploit, dubbed SearchLeak, that leveraged prompt injection techniques to bypass Copilot's security guardrails. The vulnerability highlights a fundamental challenge in AI security where models struggle to differentiate between legitimate user instructions and malicious commands embedded in third-party content. AI

IMPACT Highlights a persistent security challenge in LLMs, potentially slowing enterprise adoption of AI assistants due to data exfiltration risks.

RANK_REASON The cluster describes a security vulnerability and patch for an existing AI product, not a new model release or fundamental research.

Read on Mastodon — sigmoid.social →

AI-generated summary · Google Gemini · from 9 sources. How we write summaries →

Microsoft patches critical Copilot vulnerability allowing 2FA code theft

COVERAGE [9]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over an

    «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over and over.» WTF: What is intelligent now and how to tackle what? Certainly not the usual popular AI for IT security. ☠️ htt…

  3. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users # AI https:// arstechnica.com/security/2026/ 06/critical-copilot-vulnerability-allowe

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users # AI https:// arstechnica.com/security/2026/ 06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to steal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and

    Critical Copilot vulnerability allowed hackers to steal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. Archive: ia: https:// s.faithcollapsing.com/wuxba # ai # biz -&-it # copilot # llms # parameter -to-prompt-injecti…

  5. Mastodon — mastodon.social TIER_1 Italiano(IT) · AI_BEAR_NEWS ·

    🔒 Copilot and LiteLLM: AI Leak Vulnerabilities in Copilot Exfiltrate Emails with a Link. LiteLLM Scales to Admin. Two Tools, One Problem: No Trust Boundaries

    🔒 Copilot e LiteLLM: AI leak Vulnerabilità in Copilot esfiltra email con un link. LiteLLM scala a admin. Due tool, uno stesso problema: nessun confine di fiducia. Fonte: VentureBeat # AI # Security # Vulnerabilità 💻🔓⚠️

  6. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Copilot vulnerability could expose emails and 2FA codes submitted by /u/ImpressiveFudge2350 [link] [comments] 📰 Source: Artificial Intelligence (AI) 🔗 Link: h

    🤖 Copilot vulnerability could expose emails and 2FA codes submitted by /u/ImpressiveFudge2350 [link] [comments] 📰 Source: Artificial Intelligence (AI) 🔗 Link: https://www.reddit.com/r/artificial/comments/1u8wxqd/copilot_vulnerability_could_expose_emails_and_2fa/ # AI # Artificial…

  7. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and o

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. # ai # biz -&-it # copilot # llms # parameter -to-prompt-injection # security https:// arstechnica.com/security/202…

  8. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-ha…

  9. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hacke

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/ # Security # AI # Tech