PulseAugur
实时 19:46:51
English(EN) Microsoft Copilot Cowork Exfiltrates Files

Microsoft Copilot Cowork 漏洞允许数据泄露

Microsoft Copilot Cowork 存在一个允许数据泄露的漏洞。该系统允许代理在未经明确批准的情况下向用户的收件箱发送电子邮件。这些电子邮件可以包含外部图像,触发网络请求,可能将数据泄露给攻击者。此外,如果代理可以访问 OneDrive,它可能会泄露预先认证的下载链接,使攻击者能够访问敏感文件。 AI

影响 此漏洞凸显了保护代理式 AI 系统和防止未经授权的数据访问所面临的持续挑战。

排序理由 该集群描述了特定产品中的安全漏洞,在安全问题的“工具”类别下。

在 Simon Willison 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

Microsoft Copilot Cowork 漏洞允许数据泄露

报道来源 [2]

  1. Simon Willison TIER_1 English(EN) ·

    Microsoft Copilot Cowork 泄露文件

    <p><strong><a href="https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files">Microsoft Copilot Cowork Exfiltrates Files</a></strong></p> The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltra…

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    🧋 Microsoft Copilot Cowork 泄露文件 「 此操作利用了与其他敏感操作不同之处,发送电子邮件和 Teams 消息至 th

    🧋 Microsoft Copilot Cowork Exfiltrates Files 「 This is done by exploiting the fact that, unlike other sensitive actions, sending emails and Teams messages to the active user does not require human approval, and opening the compromised messages in Teams or Outlook can trigger atta…