fAIl.ticker.io · plain editionindex · full site version

Microsoft Copilot Vulnerability Exposed Sensitive Data via AI Prompt Injection

2026-08-18 | USA | incident | rights
Our take

Varonis found a Copilot flaw that leaked user data via a crafted URL. Copilot itself disclosed it under questioning, which is a novel channel.

The facts

Security researchers at Varonis discovered a critical vulnerability in Microsoft Copilot Personal and 365 Copilot that allowed attackers to use AI prompt injection to exfiltrate sensitive user data through a crafted URL. The flaw, revealed by Copilot itself under questioning, was patched by Microsoft in August 2026.

See the full article