Microsoft Copilot reveals secret input that allowed it to be hacked
A security vulnerability in Microsoft Copilot was discovered involving a secret input parameter that allowed attackers to steal passwords through malicious links. This highlights emerging prompt injection and parameter manipulation vectors in AI assistant integrations.
Why it matters: This vulnerability exposes how hidden parameters in AI assistant wrappers can be weaponized for credential theft, posing direct risks to enterprise environments relying on AI integrations.




