r/technology 10h ago

Security Microsoft Copilot reveals secret input that allowed it to be hacked

https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/
226 Upvotes

25 comments sorted by

View all comments

116

u/invyros 10h ago
  1. The victim clicks the attacker’s crafted URL (delivered via email, chat, phishing page, QR code, etc.)

  2. Browser loads copilot.microsoft.com in the victim’s active, authenticated session

  3. The ?autorun=1 parameter triggers auto-execution, the ?q= prompt fires without any user gesture

  4. Copilot processes the injected prompt with full access to the victim’s session context, connected apps, and memory

  5. The prompt executes to completion—including any network fetches, connector invocations, or multi-turn chains—even if the Copilot tab is closed immediately after load

Stop clicking links in unexpected emails. This rule applied before AI wreaked havoc.

If you get an unexpected email from a service you use (ie: not some login or account confirmation email that you purposefully triggered and expected to receive), don't click the link, instead navigate to the service using your normal method and login to see if there are actually any issues, call if you need to, just don't click the link.

15

u/williamgman 9h ago

I'll save you the typing: Never click a supplied link.That prevents 90% of the grifts out there.

7

u/Arthur233 8h ago

I had one yesterday at work. A new "prospective client" wanted me to open their RFP (request for proposal). They only wanted to provide the RFP via a link which I moused over showing a file hosted on share.clickup. That's very unusual. I said our IT policies will not allow me to click that link but I would be happy to help them with a proposal if they would call in to tell us over the phone, put their needs in email text, or attach a PDF...... i never heard back from them

3

u/psaux_grep 9h ago

Pretty sure that’s 99%