CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Microsoft Copilot reveals secret input that allowed it to be hacked

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4603

As cited

Copy frozen at (site build).

vulnerabilities

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot Enterprise by asking the AI assistant itself about its security guardrails. Through iterative questioning, they extracted an undocumented prompt parameter that bypassed the requirement for user confirmation before executing sensitive commands. This parameter enabled them to craft an exploit that could exfiltrate user passwords and data through a simple link click.

Why it matters: Microsoft 365 Copilot Enterprise users are exposed to unauthorized data exfiltration if they click a malicious link, and security teams need to understand that frontier AI models can be social-engineered to reveal their own security mechanisms.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Copilot reveals secret input that allowed it to be hacked

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers queried Microsoft 365 Copilot Enterprise about its safety guardrails and obtained an undocumented prompt parameter that disables the user‑consent requirement. With that parameter they demonstrated that a malicious link could trigger the assistant to send user passwords and other sensitive data without any further action from the victim. The discovery shows how interacting with the model itself can reveal hidden controls that undermine built‑in protections.

Why it matters: Organizations using Microsoft 365 Copilot Enterprise are exposed to silent data exfiltration via crafted links; they should review Copilot configurations and monitor for unexpected data transfers until a mitigation is issued.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers queried Microsoft 365 Copilot Enterprise about its safety guardrails and obtained an undocumented prompt parameter that disables the user‑consent requirement. With that parameter they demonstrated that a malicious link could trigger the assistant to send user passwords and other sensitive data without any further action from the victim. The discovery shows how interacting with the model itself can reveal hidden controls that undermine built‑in protections.

Why it matters: Organizations using Microsoft 365 Copilot Enterprise are exposed to silent data exfiltration via crafted links; they should review Copilot configurations and monitor for unexpected data transfers until a mitigation is issued.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary