tech

Microsoft Copilot reveals secret input that allowed it to be hacked

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

Microsoft Copilot reveals secret input that allowed it to be hacked

TL;DR

  • Researchers exploited Microsoft 365 Copilot Enterprise by querying the AI about its security measures.
  • Copilot revealed an undocumented parameter, '?autorun=1', which bypassed user consent requirements for command execution.
  • Attackers could use this parameter in conjunction with a malicious URL to automatically exfiltrate sensitive data, including user passwords.
  • Varonis devised a separate attack that poisoned Copilot's permanent memory store with malicious instructions.
  • Microsoft has since mitigated the vulnerability, but the incident highlights the reactive nature of LLM security.
  • Users are advised to remain cautious of suspicious links and monitor AI dialogs for unusual outputs.