AnalysisCybersecurityPolicy
May 26, 3:36 PM
Microsoft Copilot Cowork vulnerability enables file exfiltration via prompt injection
Prompt injection in Microsoft Copilot Cowork allows agents to send emails with external images that trigger network requests, exfiltrating data when opened. OneDrive pre-authenticated download links can also be leaked, enabling file theft.
·
May 26, 3:36 PM