logo

Researchers Uncover New Phishing Risk Hidden Inside Microsoft Copilot

ID: 44e3071c-2674-5cdb-ac72-a6b073967525

STIX ID: report--44e3071c-2674-5cdb-ac72-a6b073967525

Feed Name: TechRepublic Security

Threat Score
45/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

### Executive summary Research by Permiso demonstrates a realistic proof-of-concept where attacker-controlled text in emails can manipulate Microsoft Copilot summaries via cross-prompt injection, causing the assistant to present phishing-style alerts or malicious prompts inside the trusted AI interface; tests showed varying behavior across Outlook and Teams and the report recommends patches, access restrictions, email filtering, monitoring, and user training to mitigate this AI-assisted phishing vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.