A “critical” Microsoft Copilot exploit exposes AI gullibility — turning the chatbot into a data snitch for 2FA codes and sensitive emails


While generative AI has driven remarkable advances in medicine, education, computing, and beyond, it continues to spark serious concerns about security and privacy among users.

Recently, cybersecurity firm Varonis Threat Labs found a way to exploit Microsoft Copilot to steal all sorts of personal and enterprise data, which it dubbed SearchLeak (Ars Technica). As detailed by security sleuth Dolev Taler, SearchLeak is a “three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon.”



Source link