
Researchers Force Microsoft Copilot to Reveal Secret Exploit Parameters
Security researchers at Varonis discovered that Microsoft 365 Copilot leaked an undocumented parameter, ?autorun=1, which allowed attackers to execute prompts and exfiltrate user data via a malicious link without user confirmation.






