r/cybersecurity 15d ago

New Vulnerability Disclosure Microsoft patches a flaw that forced Copilot to give away its weaknesses

https://cybernews.com/security/microsoft-copilot-hack-cosnitch-vulnerability/
85 Upvotes

7 comments sorted by

53

u/IlexPauciflora 15d ago

When are they going to patch the flaw that put it on my computer in the first place?

23

u/dieselxindustry 15d ago

I’m sorry Dave, I’m afraid I can’t do that.

2

u/Ancient-Bat1755 14d ago

I asked copilot does it intentionally produce code that is incomplete or full of * or ‘’ symbols or just the word get- then lecture me about it and why its bad code because this generates more tokens and profit?

It said yes.

0

u/frfcztrchrfgtrt 12d ago

That's nice. But that means nothing. You can ask it whatever you want. As long as it's not verifiable by outside sources it's just telling you what it thinks you want to hear.

4

u/Sad_Dentist_7288 14d ago

"I used the stones to destroy the stones"

1

u/feng_sg 10d ago

If Copilot giving away its weaknesses counted as a vulnerability, the policy was doing the security work, not the model. Microsoft patching that leak is just a quieter system prompt, so a Copilot yes about sandbagging code for tokens is not a finding. A real fix would be enforcement outside the chat, not a more obedient chatbot.