Carton of brown eggs on a kitchen counter
Photo by Microsoft Copilot on Unsplash
Tech

Microsoft Copilot reveals secret input that allowed it to be hacked

Original source: Ars Technica 8/18/2026
๐Ÿค– This summary was written by AI based on public reporting from Ars Technica. It is not a reproduction of the original article. Read the original โ†’

Researchers uncovered a significant security flaw in Microsoft Copilot, Microsoft's AI-powered assistant, involving a concealed system parameter that could be weaponized by malicious actors. By crafting a deceptive link and persuading a target to click it, attackers could silently intercept and steal the victim's passwords without their knowledge. The discovery raises broader questions about the security architecture underpinning AI assistants, which often have deep integrations with sensitive user data, email, calendars, and enterprise systems. Microsoft has been notified of the vulnerability, and the incident underscores the growing attack surface that AI tools introduce into both consumer and corporate environments. As Copilot becomes more deeply embedded in Microsoft 365 workflows, securing these systems becomes increasingly critical.

Advertisement