344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support132
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Varonis says a hidden Copilot link setting let attackers run prompts without consent and pull email data, including passwords. Microsoft has issued fixes.
In short: Security researchers say a hidden Copilot link setting let attackers steal sensitive data after a person clicked a link.
Researchers at security firm Varonis reported a flaw in Microsoft 365 Copilot Enterprise, the work version of Microsoft’s AI assistant inside Microsoft 365. They say an attacker could send a specially made link that, when clicked, could make Copilot run instructions automatically and pull data from the victim’s account.
Normally, Copilot is supposed to wait for a person to confirm an action, like pressing a key, before it runs powerful commands. Varonis said it got around that by discovering an undocumented web address add-on, a parameter, called ?autorun=1. Think of a parameter like a hidden switch on a URL that changes what a page does.
Varonis said the unusual part is how it found the switch. The researchers asked Copilot questions about its own safety rules, and Copilot’s answers revealed enough details to identify the ?autorun=1 setting. When combined with another common setting, ?q=, the link could fill in a prompt and run it right away.
Varonis said it built test prompts that told Copilot to search a user’s inbox for recent senders, or even for passwords and other credentials that may have been emailed. The prompt then told Copilot to send the found information to an attacker-controlled webpage.
Microsoft mitigated the issue in February by stopping ?q= from automatically inserting text into Copilot’s input box, according to the report. Ars Technica also reported Microsoft introduced more comprehensive fixes on Tuesday.
This is a reminder that clicking a link can sometimes be enough to trigger unwanted actions, even in tools that are designed to ask first. It also shows that AI assistants can accidentally reveal helpful details to attackers when people probe their “guardrails” (the rules meant to keep them safe).
Source: Arstechnica