Microsoft has patched a critical vulnerability in its M365 Copilot AI platform that allowed hackers to steal two-factor authentication (2FA) codes and other sensitive data. Researchers demonstrated an exploit, dubbed SearchLeak, that leveraged prompt injection techniques to bypass Copilot's security guardrails. The vulnerability highlights a fundamental challenge in AI security where models struggle to differentiate between legitimate user instructions and malicious commands embedded in third-party content. AI
IMPACT Highlights a persistent security challenge in LLMs, potentially slowing enterprise adoption of AI assistants due to data exfiltration risks.
RANK_REASON The cluster describes a security vulnerability and patch for an existing AI product, not a new model release or fundamental research.
Read on Mastodon — sigmoid.social →
- Ars Technica
- Copilot
- GitHub
- GitHub Copilot
- M365 Copilot
- Microsoft
- SearchLeak
- two-factor authentication
- Varonis
AI-generated summary · Google Gemini · from 9 sources. How we write summaries →