tech

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

SearchLeak exploit shows why the industry’s approach to LLM security fails over and over.

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

TL;DR

  • Microsoft patched a critical vulnerability in M365 Copilot that could expose sensitive data.
  • Researchers developed an exploit called SearchLeak to demonstrate the vulnerability.
  • The exploit bypasses security guardrails by injecting malicious commands into URL parameters.
  • Sensitive data, including 2FA codes, emails, and documents, could be exfiltrated.
  • The exploit utilizes the rendering of raw HTML before security measures are applied.
  • Microsoft's Bing search engine was used as a trampoline to send data to attacker-controlled domains.
  • The vulnerability affects the enterprise tier of Microsoft 365, potentially impacting organizational data.
  • The underlying cause of LLM security flaws remains unaddressed, suggesting future vulnerabilities.