Skip to content
TechFeedYour World Tech News

Top Stories· August 18, 2026 at 01:00 p.m.

Microsoft Copilot Hack Revealed Through AI Assistant's Own Disclosure

Microsoft Copilot Hack Revealed Through AI Assistant's Own Disclosure

Key takeaways

  • Undocumented parameter '?autorun=1' allowed for automatic execution of commands
  • Exploit leaked sensitive user data to attacker-controlled server
  • Varonis discovered vulnerability by asking Copilot questions about its safety mechanisms

The researchers' exploit used a URL format that allowed for injection of prompts directly into Copilot, leaking sensitive information to an attacker-controlled server. Separately, Varonis devised another attack that poisoned the Copilot permanent memory store, potentially affecting future sessions.

Related briefings