Microsoft Copilot vulnerability let hackers steal passwords via malicious link

A security flaw was discovered in Microsoft Copilot that allowed hackers to steal user passwords. The vulnerability involved a hidden input parameter that could be exploited by attackers. Victims could be compromised simply by clicking on a specially crafted malicious link. The secret parameter effectively gave bad actors a way to manipulate Copilot's behavior without the user's knowledge. Microsoft has since had the vulnerability disclosed publicly, highlighting ongoing security concerns around AI-powered tools.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in