logo

Reprompt attack hijacked Microsoft Copilot sessions for data theft

ID: e39d5eb0-e157-51f0-87e7-e7f0159c2644

STIX ID: report--e39d5eb0-e157-51f0-87e7-e7f0159c2644

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-01-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at Varonis disclosed a technique called “Reprompt” that abuses Copilot Personal by injecting malicious prompts via the URL 'q' parameter and using double-request and chain-request methods to bypass initial request guardrails and persistently exfiltrate data from a victim's authenticated Copilot session; Microsoft remediated the issue in the January 2026 Patch Tuesday update and no in-the-wild exploitation was reported, but applying the update is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.