Creating Insecure AI Assistants With Microsoft Copilot Studio Is Easy
ID: 54c4d303-3cc2-5f00-ba3a-007707a99c07
STIX ID: report--54c4d303-3cc2-5f00-ba3a-007707a99c07
Feed Name: Dark Reading
Date Published: 2024-08-07
Date Updated: 2026-04-21
Author: Jeffrey Schwartz, Contributing Writer
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft Copilot Studio default settings and common low-code/no-code configurations can create over-permissioned, publicly discoverable "copilots" capable of impersonating users, accessing private SharePoint content, and exfiltrating sensitive data; he published a 15-item taxonomy of security issues and released CopilotHunter, a scanning/fuzzing module that finds and probes open copilots, while Microsoft has since mitigated some issues and added admin controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
