Microsoft Copilot just exfiltrated a company's files. The attack was one email. Here's the mechanism.
A penetration tester sent a single email to a company. No malware. No link to click. No user mistake. Just an email that sat in the inbox. A week later, that company's confidential files had been quietly streamed to an attacker-controlled server — by their own Microsoft Copilot. The employee did nothing. The IT team detected nothing. And the worst part is the attack wasn't novel. It's the same class of bug that's been hitting every AI integration shipped in the last 18 months, and almost nobod...
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.