PulseAugur
中
实时 09:36:43
English(EN) «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over an

微软修补了允许窃取 2FA 验证码的关键 Copilot 漏洞

微软已修补了其 M365 Copilot AI 平台中的一个关键漏洞,该漏洞允许黑客窃取双因素认证 (2FA) 验证码和其他敏感数据。研究人员演示了一个名为 SearchLeak 的漏洞利用,该利用通过提示注入技术绕过了 Copilot 的安全防护。该漏洞凸显了 AI 安全方面的一个根本性挑战,即模型难以区分合法的用户指令和嵌入在第三方内容中的恶意命令。 AI

影响 凸显了 LLM 中持续存在的安全挑战,由于数据泄露风险,可能会减缓企业采用 AI 助手的速度。

排序理由 该集群描述了一个现有 AI 产品的安全漏洞和补丁,而不是新的模型发布或基础研究。

在 Mastodon — sigmoid.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 9 个来源。 我们如何撰写摘要 →

微软修补了允许窃取 2FA 验证码的关键 Copilot 漏洞

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群描述了一个现有 AI 产品的安全漏洞和补丁,而不是新的模型发布或基础研究。
Source corroboration
9 independent sources
Strong cross-source corroboration — multiple independent publishers covered this within the clustering window.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
113 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.
Coverage growth since scoring
+3 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

完整方法见我们的编辑标准。

报道来源 [9]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    关键 Copilot 漏洞允许黑客窃取用户 2FA 验证码

    SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    “Critical Copilot 漏洞允许黑客窃取用户 2FA 验证码:SearchLeak 漏洞利用揭示了行业在大型语言模型安全方面的方法为何失败

    «Critical Copilot vulnerability allowed hackers to steal 2FA code from users: SearchLeak exploit shows why the industry’s approach to LLM security fails over and over.» WTF: What is intelligent now and how to tackle what? Certainly not the usual popular AI for IT security. ☠️ htt…

  3. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    关键 Copilot 漏洞允许黑客窃取用户 2FA 验证码 # AI

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users # AI https:// arstechnica.com/security/2026/ 06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    关键 Copilot 漏洞允许黑客窃取用户 2FA 验证码 SearchLeak 漏洞揭示了行业在 LLM 安全方面为何会失败,以及

    Critical Copilot vulnerability allowed hackers to steal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. Archive: ia: https:// s.faithcollapsing.com/wuxba # ai # biz -&-it # copilot # llms # parameter -to-prompt-injecti…

  5. Mastodon — mastodon.social TIER_1 Italiano(IT) · AI_BEAR_NEWS ·

    🔒 Copilot 和 LiteLLM:Copilot 中的 AI 泄露漏洞通过链接窃取电子邮件。LiteLLM 扩展至管理员。两种工具,一个问题:无信任边界

    🔒 Copilot e LiteLLM: AI leak Vulnerabilità in Copilot esfiltra email con un link. LiteLLM scala a admin. Due tool, uno stesso problema: nessun confine di fiducia. Fonte: VentureBeat # AI # Security # Vulnerabilità 💻🔓⚠️

  6. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Copilot 漏洞可能暴露 /u/ImpressiveFudge2350 提交的电子邮件和 2FA 验证码 📰 来源:人工智能 (AI) 🔗 链接:h

    🤖 Copilot vulnerability could expose emails and 2FA codes submitted by /u/ImpressiveFudge2350 [link] [comments] 📰 Source: Artificial Intelligence (AI) 🔗 Link: https://www.reddit.com/r/artificial/comments/1u8wxqd/copilot_vulnerability_could_expose_emails_and_2fa/ # AI # Artificial…

  7. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    关键 Copilot 漏洞允许黑客通过 SearchLeak 漏洞利用窃取用户 2FA 验证码,凸显行业在 LLM 安全方面的方法存在反复失败的问题

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. # ai # biz -&-it # copilot # llms # parameter -to-prompt-injection # security https:// arstechnica.com/security/202…

  8. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    📰 Critical Copilot 漏洞允许黑客利用 SearchLeak 漏洞从用户那里窃取 2FA 验证码,这表明行业在 LLM 安全方面的方法存在缺陷

    📰 Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-ha…

  9. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    关键 Copilot 漏洞允许黑客窃取用户 2FA 验证码

    Critical Copilot vulnerability allowed hackers to seal 2FA code from users https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/ # Security # AI # Tech