PulseAugur
EN
LIVE 14:32:46

Microsoft patches critical Copilot vulnerability allowing 2FA code theft

Microsoft has patched a critical vulnerability in its M365 Copilot AI platform that allowed hackers to steal two-factor authentication (2FA) codes and other sensitive data. Researchers demonstrated an exploit, dubbed SearchLeak, that leveraged prompt injection techniques to bypass Copilot's security guardrails. The vulnerability highlights a fundamental challenge in AI security where models struggle to differentiate between legitimate user instructions and malicious commands embedded in third-party content. AI

IMPACT Highlights a persistent security challenge in LLMs, potentially slowing enterprise adoption of AI assistants due to data exfiltration risks.

RANK_REASON The cluster describes a security vulnerability and patch for an existing AI product, not a new model release or fundamental research.

Read on Mastodon — sigmoid.social →

AI-generated summary · Google Gemini · from 9 sources. How we write summaries →

Microsoft patches critical Copilot vulnerability allowing 2FA code theft

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
The cluster describes a security vulnerability and patch for an existing AI product, not a new model release or fundamental research.
Source corroboration
9 independent sources
Strong cross-source corroboration — multiple independent publishers covered this within the clustering window.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
102 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.
Coverage growth since scoring
+3 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

Full methodology in our editorial standards.

COVERAGE [9]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over an

    «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over and over.» WTF: What is intelligent now and how to tackle what? Certainly not the usual popular AI for IT security. ☠️ htt…

  3. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users # AI https:// arstechnica.com/security/2026/ 06/critical-copilot-vulnerability-allowe

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users # AI https:// arstechnica.com/security/2026/ 06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to steal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and

    Critical Copilot vulnerability allowed hackers to steal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. Archive: ia: https:// s.faithcollapsing.com/wuxba # ai # biz -&-it # copilot # llms # parameter -to-prompt-injecti…

  5. Mastodon — mastodon.social TIER_1 Italiano(IT) · AI_BEAR_NEWS ·

    🔒 Copilot and LiteLLM: AI Leak Vulnerabilities in Copilot Exfiltrate Emails with a Link. LiteLLM Scales to Admin. Two Tools, One Problem: No Trust Boundaries

    🔒 Copilot e LiteLLM: AI leak Vulnerabilità in Copilot esfiltra email con un link. LiteLLM scala a admin. Due tool, uno stesso problema: nessun confine di fiducia. Fonte: VentureBeat # AI # Security # Vulnerabilità 💻🔓⚠️

  6. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Copilot vulnerability could expose emails and 2FA codes submitted by /u/ImpressiveFudge2350 [link] [comments] 📰 Source: Artificial Intelligence (AI) 🔗 Link: h

    🤖 Copilot vulnerability could expose emails and 2FA codes submitted by /u/ImpressiveFudge2350 [link] [comments] 📰 Source: Artificial Intelligence (AI) 🔗 Link: https://www.reddit.com/r/artificial/comments/1u8wxqd/copilot_vulnerability_could_expose_emails_and_2fa/ # AI # Artificial…

  7. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and o

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. # ai # biz -&-it # copilot # llms # parameter -to-prompt-injection # security https:// arstechnica.com/security/202…

  8. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-ha…

  9. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hacke

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/ # Security # AI # Tech