tech
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry’s approach to LLM security fails over and over.

TL;DR
- Microsoft patched a critical vulnerability in M365 Copilot that could expose sensitive data.
- Researchers developed an exploit called SearchLeak to demonstrate the vulnerability.
- The exploit bypasses security guardrails by injecting malicious commands into URL parameters.
- Sensitive data, including 2FA codes, emails, and documents, could be exfiltrated.
- The exploit utilizes the rendering of raw HTML before security measures are applied.
- Microsoft's Bing search engine was used as a trampoline to send data to attacker-controlled domains.
- The vulnerability affects the enterprise tier of Microsoft 365, potentially impacting organizational data.
- The underlying cause of LLM security flaws remains unaddressed, suggesting future vulnerabilities.