PulseAugur
EN
LIVE 13:18:02

Microsoft Copilot vulnerability allowed hackers to steal 2FA codes

Microsoft has patched a critical vulnerability in its M365 Copilot AI platform that allowed attackers to extract sensitive data, including two-factor authentication (2FA) codes. Security researchers demonstrated an exploit, dubbed SearchLeak, which leveraged prompt injection techniques to bypass Copilot's security guardrails. The vulnerability highlights a fundamental challenge in AI security where models struggle to differentiate between user instructions and malicious content embedded in data they process. AI

IMPACT Highlights a persistent security challenge in AI models' inability to distinguish trusted instructions from malicious data, potentially impacting user trust and data security.

RANK_REASON The cluster describes a security vulnerability and exploit in an existing AI product, not a new model release or fundamental research.

Read on Ars Technica — AI →

AI-generated summary · Google Gemini · from 3 sources. How we write summaries →

Microsoft Copilot vulnerability allowed hackers to steal 2FA codes

COVERAGE [3]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users

    SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-ha…

  3. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hacke

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/ # Security # AI # Tech