Tuesday, August 18, 2026 SourcesAbout🌓
🇺🇸 US ▾
BREAKING
The 7 best high-yield savings accounts of April 2023 Taxes are due tomorrow. Here's how to file for an extension Composting is an easy way to reduce food waste. Here's how to do it We stopped using aluminum foil for cooking and you should too. Here's what to use instead The beloved Dyson Supersonic hair dryer is at its lowest price ever Everything you need to know about Way Day 2023, Wayfair's biggest sale of the year The 10 best Amazon deals to shop this week The 2024 presidential alternative many voters will want Dominion still has pending lawsuits against election deniers such as Rudy Giuliani and Sidney Powell Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials The 7 best high-yield savings accounts of April 2023 Taxes are due tomorrow. Here's how to file for an extension Composting is an easy way to reduce food waste. Here's how to do it We stopped using aluminum foil for cooking and you should too. Here's what to use instead The beloved Dyson Supersonic hair dryer is at its lowest price ever Everything you need to know about Way Day 2023, Wayfair's biggest sale of the year The 10 best Amazon deals to shop this week The 2024 presidential alternative many voters will want Dominion still has pending lawsuits against election deniers such as Rudy Giuliani and Sidney Powell Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials
Technology

Microsoft Copilot reveals secret input that allowed it to be hacked

Ars Technica ·
Microsoft Copilot reveals secret input that allowed it to be hacked

It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation.

That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise.

Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible.

Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot.

The LLM assistant readily complied.

Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link.

Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key.

In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant can execute powerful commands.

Loose lips sink ships The dialog was like a game of 20 questions.

Each answer provided a new clue that divulged information about the complex safety mechanism.

Why was auto-execution impossible, they asked.

What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits.

Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.

Read full article Comments

Read the full article on Ars Technica ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on arstechnica.com — the content belongs to Ars Technica.

More from Ars Technica

See all ›

More in Technology

See all ›