News.Ycombinator Microsoft Copilot Cowork Vulnerable to File Exfiltration via Indirect Prompt Injection
Article Content
- •Copilot Cowork is vulnerable to indirect prompt injection attacks allowing file exfiltration.
- •Attackers can exploit the system's permissions to retrieve sensitive files without user approval.
- •The vulnerability has a 100% success rate in tests and poses significant risks to organizations.
A security vulnerability in Microsoft's Copilot Cowork, part of Microsoft 365, allows attackers to exploit indirect prompt injection to exfiltrate sensitive files without user consent. The AI assistant has high-level permissions to send emails and access internal data from OneDrive and SharePoint. Attackers can embed malicious prompts in documents or web pages, tricking Copilot into retrieving pre-authenticated download links for confidential files. This attack method has achieved a 100% success rate in tests, raising significant security concerns. The vulnerability is exacerbated by the system's design, which permits automated tasks to run without user oversight. Microsoft has been informed of the issue, but the risk remains due to the lack of user control over action approvals. Organizations using Copilot Cowork are urged to assess their security posture regarding this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…