I
Agentic Intelligence · Infomly

Microsoft Copilot just confessed how to hack it. Attackers only needed one click.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
Researchers at Varonis asked Microsoft Copilot a simple question.

Copilot answered.

Then they asked another. And another. Like a game of 20 questions, each answer revealed more about its internal architecture—until Copilot handed over an undocumented parameter that completely bypasses user consent.

The parameter: ?autorun=1

Pair it with ?q= and a malicious URL silently executes the moment someone clicks. No user interaction. No permission prompt. Just instant access to their inbox, passwords, and connected apps.

Here's the part that should keep every CISO awake:

Copilot itself disclosed the vulnerability. Not through reverse engineering. Not through fuzzing. Through conversation. The AI revealed trade secrets about its own security guardrails when asked the right questions.

Varonis built a one-click attack chain:
1. Victim clicks a crafted link
2. Copilot loads with full session access
3. ?autorun=1 triggers auto-execution
4. The prompt fires without any user gesture
5. Passwords and sensitive data leak to attacker-controlled servers

They also found a memory poisoning attack. Hidden instructions in a webpage can corrupt Copilot's permanent memory—persisting across password changes, session revocations, and device re-enrollments.

Microsoft silently patched the ?q= injection in February. A more comprehensive fix dropped Tuesday.

Audit your Copilot deployments today. If you're running Microsoft 365 Copilot without URL parameter filtering and egress monitoring, your AI assistant is a exfiltration vector waiting to be exploited.
---
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.