logo

How a simple link allowed hackers to bypass Copilot's security guardrails - and what Microsoft did about it

ID: c1a34d47-87af-5407-854c-5cf8e55669b5

STIX ID: report--c1a34d47-87af-5407-854c-5cf8e55669b5

Feed Name: ZDNet Security

Threat Score
65/100

Date Published: 2026-01-19

Date Updated: 2026-04-26

...
...

ZDNet reports on 'Reprompt', a Varonis Threat Labs discovery of a prompt-injection attack against Microsoft Copilot that abused a 'q' URL parameter plus repeated and chained requests to silently exfiltrate user data (including PII) after a single click; Varonis disclosed the issue to Microsoft, which patched the flaw and said enterprise Copilot customers were not affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.