Reprompt attack hijacked Microsoft Copilot sessions for data theft
ID: e39d5eb0-e157-51f0-87e7-e7f0159c2644
STIX ID: report--e39d5eb0-e157-51f0-87e7-e7f0159c2644
Feed Name: Bleeping Computer
Threat Score
Researchers at Varonis disclosed a technique called “Reprompt” that abuses Copilot Personal by injecting malicious prompts via the URL 'q' parameter and using double-request and chain-request methods to bypass initial request guardrails and persistently exfiltrate data from a victim's authenticated Copilot session; Microsoft remediated the issue in the January 2026 Patch Tuesday update and no in-the-wild exploitation was reported, but applying the update is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
