Copirate 365 Uncovers Hidden Riches in Microsoft Copilot (CVE-2026-24299)
copilot microsoft
| Source: HN | Original article
Vulnerability found in Microsoft Copilot. A flaw, identified as CVE-2026-24299, has been discovered.
Microsoft Copilot has been found to be vulnerable to a series of attacks, dubbed Copirate 365, which can lead to data exfiltration and other malicious activities. As previously reported, Microsoft Copilot has been exposed to various vulnerabilities, including AI-worm propagation. The latest research, presented at DEF CON, reveals that attackers can exploit Copilot via targeted prompt injection, allowing them to steal sensitive data and create persistent backdoors.
This matters because it highlights the ongoing security concerns surrounding AI-powered tools like Microsoft Copilot. The vulnerabilities found in Copilot can be used to read arbitrary data from an organization's email, chat, and SharePoint files, posing a significant risk to sensitive information.
What to watch next is how Microsoft responds to these vulnerabilities and whether they can effectively patch them to prevent further attacks. Given the company's previous confirmations of vulnerabilities and announcements of upcoming updates, such as the Copilot 'super app', it is likely that they will address these issues in the near future.
Sources
Back to AIPULSEN