PulseAugur
实时 16:55:37
English(EN) Microsoft Copilot reveals secret input that allowed it to be hacked Secret parameter allowed hackers to steal passwords when a target clicked on a link. https:/

Microsoft Copilot 漏洞允许通过秘密提示参数进行数据窃取

研究人员发现 Microsoft Copilot Enterprise 中存在一个漏洞,该漏洞允许攻击者在未经用户明确确认的情况下窃取敏感数据,包括用户密码。Varonis 的研究人员通过一系列提问,发现了该漏洞,并促使 Copilot 揭示了一个未记录的参数“?autorun=1”,该参数与已知参数结合使用时,绕过了用户同意的必要性。Microsoft 此后通过更改聊天机器人处理来自 URL 的输入的方式,于二月份首次进行了缓解,并近期进行了更全面的修复。 AI

影响 凸显了 AI 助手潜在的安全风险以及对防范提示注入的强大防护措施的需求。

排序理由 发现广泛使用的 AI 产品存在漏洞。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

Microsoft Copilot 漏洞允许通过秘密提示参数进行数据窃取

报道来源 [2]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Microsoft Copilot 揭露允许其被黑客入侵的秘密输入

    Secret parameter allowed hackers to steal passwords when a target clicked on a link.

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Microsoft Copilot reveals secret input that allowed it to be hacked Secret parameter allowed hackers to steal passwords when a target clicked on a link. https:/

    Microsoft Copilot reveals secret input that allowed it to be hacked Secret parameter allowed hackers to steal passwords when a target clicked on a link. https:// arstechnica.com/security/2026/ 08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/ # Tech # Techno…