logo

Creating Insecure AI Assistants With Microsoft Copilot Studio Is Easy

ID: 54c4d303-3cc2-5f00-ba3a-007707a99c07

STIX ID: report--54c4d303-3cc2-5f00-ba3a-007707a99c07

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-08-07

Date Updated: 2026-04-21

Author: Jeffrey Schwartz, Contributing Writer

...
...

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft Copilot Studio default settings and common low-code/no-code configurations can create over-permissioned, publicly discoverable "copilots" capable of impersonating users, accessing private SharePoint content, and exfiltrating sensitive data; he published a 15-item taxonomy of security issues and released CopilotHunter, a scanning/fuzzing module that finds and probes open copilots, while Microsoft has since mitigated some issues and added admin controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.