Experts manage to hack Microsoft Copilot by continually asking it questions about itself



  • Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data
  • Exploit used malicious URLs and persistent memory poisoning to bypass guardrails
  • Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models

Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.

Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named CoSnitch.

https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1600-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img