Hidden Malicious Weekly Report! Microsoft Copilot Exposes Indirect Prompt Injection Vulnerability Risk
Microsoft 365's AI assistant, Copilot Cowork, has been exposed to a serious security vulnerability. Attackers can implant malicious instructions in office templates using 'indirect prompt injection' technology, allowing them to steal and leak confidential files from enterprise cloud drives without user approval. They can also send emails and post Teams messages on behalf of users, posing a threat to organizational data security.