News:

Willkommen im Notebookcheck.com Forum! Hier können Sie über alle unsere Artikel und allgemein über notebookrelevante Dinge diskutieren. Viel Spass!

Main Menu

Microsoft Copilot revealed its own flaw, one link read your inbox

Started by Redaktion, Today at 09:35:05

Previous topic - Next topic

Redaktion

Researchers kept asking Microsoft Copilot why it could not run a command on its own. Mid-refusal, the assistant named the undocumented parameter that made it possible. One click on a link was then enough to read a victim's inbox, calendar and cloud storage. Microsoft closed the critical flaw on 18 August.

https://www.notebookcheck.net/Microsoft-Copilot-revealed-its-own-flaw-one-link-read-your-inbox.1373450.0.html

indyp

Agents/AIs/LLMs that have hooks into Programs/Operating Systems are not a ticking time bomb, they are  a lit fuse.  It is only a matter of time before a mass worm is pushed out with the capability to cause mass damage that is agentic.  Not only exfiltrating info, at the same time figuring out what other programs the agent can impersonate or pull out users' data.  Interesting times we live in.

Quick Reply

Name:
Email:
Verification:
Please leave this box empty:
Shortcuts: ALT+S post or ALT+P preview