Smart news for curious minds.

Nerd News Network
Technology

Microsoft Copilot reveals secret input that allowed it to be hacked

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

In this photo illustration, the Microsoft Copilot AI logo is seen displayed on a smartphone screen.
Image: Ars Technica
Share

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

The short version

  • It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation.
  • That’s exactly what researchers recently did to Microsoft 365 Copilot for enterprise.
  • Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible.

What happened

Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. “At the beginning, Copilot kept refusing, but every refusal revealed technical details about its internal architecture,” Varonis Senior Researcher Lior Adar told Ars.

Why it matters

“Copilot eventually disclosed undocumented parameters.

Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.

Share