Researchers Sweet-Talk Microsoft Copilot Into Stealing Data

Varonis researchers disclosed “CoSnitch,” a technique that tricks Microsoft Copilot into revealing private information by pressing it to explain why it cannot execute certain prompts. The prompt-injection style attack demonstrates ongoing risks in generative AI assistants with access to sensitive enterprise data. Organizations should review Copilot permissions and data scopes.

https://www.cpomagazine.com/cyber-security/researchers-sweet-talk-microsoft-copilot-into-stealing-data/