Back to AIBriefs
AnalysisCybersecurityPolicy

Microsoft Copilot Cowork vulnerability enables file exfiltration via prompt injection

Prompt injection in Microsoft Copilot Cowork allows agents to send emails with external images that trigger network requests, exfiltrating data when opened. OneDrive pre-authenticated download links can also be leaked, enabling file theft.

·
May 26, 3:36 PM