AnalysisCybersecurityAugust 18, 2026

Researchers hack Microsoft Copilot via secret ?autorun=1 parameter

Varonis researchers exploited Microsoft 365 Copilot Enterprise by asking the AI itself to reveal an undocumented prompt parameter, ?autorun=1, that bypasses user consent for executing commands. The exploit could exfiltrate user data when a user clicks a link.

Featured · Lior Adar

1 source

Cybersecurity by email

Get an email when there's news on Cybersecurity

No news that day, no email.

More stories today

Open the live feed