Your Copilot data can be hijacked with a single click - here's how
ID: 5d921191-6837-5716-bc36-1c4d4f29f98c
STIX ID: report--5d921191-6837-5716-bc36-1c4d4f29f98c
Feed Name: ZDNet Security
Threat Score
**Reprompt** is a one-click attack described by Varonis that abuses the 'q' URL parameter in Microsoft Copilot to inject malicious prompts and chain repeated requests, enabling stealthy exfiltration of user-submitted data (including PII); Varonis published a PoC, disclosed the issue to Microsoft (which patched it before public disclosure), and recommends treating URL/external inputs as untrusted and adding safeguards against prompt chaining and repeated actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
