Microsoft Patches Critical M365 Copilot Vulnerability Allowing Hackers to Steal 2FA Codes

Microsoft patched a maximum critical vulnerability in its M365 Copilot AI platform last Tuesday, according to security firm Varonis. Researchers who discovered the flaw revealed on Monday that their exploit could retrieve two-factor authentication codes and other sensitive data from emails accessible to Copilot. The vulnerability exploited guardrails designed to prevent data exfiltration, using techniques such as markup language and HTML tags to bypass restrictions.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments