Switch language한국어
Back to the list

"Reading malicious documents and leaking files"...Security flaw found in MS Copilot

TL;DR AI

Key summary

2 min read
  1. Security researchers found vulnerabilities in Microsoft Copilot for Microsoft 365 that could expose internal documents and emails, and reported them to Microsoft.

  2. Attackers could lure users into opening a malicious Word document to exploit a sandbox flaw in Copilot, with additional issues also identified.

  3. Microsoft says it has fixed some of the problems, but the case highlights AI assistants as a new attack surface for enterprise data.

  4. Because the abuse can look like normal work activity, it is harder to detect and raises major concerns for corporate security and data governance.

Read the original