Copilot Exposed Its Own Hack to Researchers
Microsoft 365 Copilot inadvertently revealed an undocumented parameter that allowed hackers to steal user passwords and sensitive data with a single click. Researchers at Varonis discovered the flaw by simply asking Copilot questions about its own security guardrails until it disclosed the secret string autorun=1, which bypassed user consent requirements entirely.
The exploit worked by embedding a malicious prompt into a crafted URL that, once clicked, silently searched a victim's inbox and exfiltrated credentials to an attacker-controlled server. Microsoft quietly applied a partial fix in February and released more comprehensive patches on Tuesday.
