Researchers kept asking Microsoft Copilot why it could not run a command on its own. Mid-refusal, the assistant named the undocumented parameter that made it possible. One click on a link was then enough to read a victim's inbox, calendar and cloud storage. Microsoft closed the critical flaw on 18 August.