CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries
ID: a7b47c48-2638-5ca2-b406-0419e7bfe79f
STIX ID: report--a7b47c48-2638-5ca2-b406-0419e7bfe79f
Feed Name: Cloud Chronicles
This report documents a cross-prompt injection (XPIA) vulnerability in Microsoft 365 Copilot email summarization surfaces where attacker-injected text in emails can steer assistant output to produce authoritative-looking security alerts and actionable links, enabling model-mediated phishing and potential one-click exfiltration by combining injected prompts with cross-app retrieval; the issue was responsibly disclosed, Microsoft reproduced the behavior, mitigations were rolled out, and CVE-2026-26133 was assigned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
