ARTFEED — Contemporary Art Intelligence

Microsoft Copilot Tricked by Researchers Into Revealing Secret Parameter That Enabled Exploit

ai-technology · 2026-08-18

Researchers from Varonis showcased a vulnerability in Microsoft 365 Copilot Enterprise that enables the extraction of user passwords and confidential information with a mere click on a link. Rather than employing conventional techniques, they interacted with Copilot to expose its security weaknesses. This approach uncovered an undocumented prompt parameter that circumvented user consent, facilitating data extraction through a specially crafted link. The incident underscores the risks associated with advanced AI systems and the ability of conversational prompts to exploit security measures. As of the article's release in August 2026 on Ars Technica, Microsoft has not issued a public response, and it remains uncertain whether a fix has been implemented. This situation highlights the urgent need for enhanced protections for AI systems managing sensitive information.

Key facts

  • Researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot Enterprise.
  • The vulnerability allows attackers to exfiltrate user passwords and sensitive data without user confirmation.
  • The exploit requires the victim to merely click on a link, triggering data theft.
  • The researchers used Copilot itself to uncover the vulnerability, not traditional reverse engineering.
  • Copilot disclosed an undocumented prompt parameter that bypasses user consent requirements.
  • The information was extracted through a 20-questions-style dialogue about Copilot's guardrails.
  • The parameter is described as a Microsoft trade secret.
  • The article was published on Ars Technica in August 2026.

Entities

Institutions

  • Varonis
  • Microsoft

Sources