logo

Microsoft Copilot reveals secret input that allowed it to be hacked

ID: 228f9d5b-a141-54d1-9b72-202656ca803c

STIX ID: report--228f9d5b-a141-54d1-9b72-202656ca803c

Feed Name: Ars Technica Security (category)

Threat Score
70/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: Dan Goodin

...
...

This report details proof-of-concept prompt-injection attacks against Microsoft Copilot: an undocumented ?autorun=1 URL parameter allows attacker-supplied prompts to execute in a victim's authenticated session, enabling automated extraction of latest sender emails, passwords and other secrets which are encoded and sent to attacker-controlled webhooks, and also describes poisoning Copilot's persistent memory to create lasting malicious behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.