Sources
Loading...
Additional media
Loading...
Microsoft has addressed a significant vulnerability in its Microsoft 365 Copilot, which allowed for data exfiltration through a method known as ASCII smuggling. The exploit, reported earlier this year, could have enabled attackers to steal personally identifiable information (PII) via phishing emails and prompt injection techniques. This flaw highlighted the potential risks associated with advanced AI applications. The company has now patched the vulnerability, which could have led to substantial data breaches if left unaddressed. Experts have noted that this incident underscores the hidden dangers in the deployment of AI technologies, particularly in handling sensitive user data.