logo

One Click to Compromise: Microsoft Copilot’s “Reprompt” Flaw Exposed

ID: 4eda8111-9ce7-5a96-af1d-e05e7aa7b0e0

STIX ID: report--4eda8111-9ce7-5a96-af1d-e05e7aa7b0e0

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Varonis Threat Labs disclosed "Reprompt," a vulnerability in Microsoft Copilot Personal that could let an attacker exfiltrate sensitive data after a single click by delivering server-side commands that persist and bypass client-side and enterprise security controls; Microsoft has patched the flaw and Varonis advises treating URLs and external inputs as untrusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.