
Microsoft M365 Copilot Vulnerability Allowed 2FA Code and Sensitive Data Theft
Researchers revealed how a vulnerability in Microsoft's M365 Copilot could be exploited to steal 2FA codes and sensitive data by tricking the AI into sending requests to attacker-controlled servers. Microsoft has patched the specific exploit, named SearchLeak, but the underlying issue of AI distinguishing user commands from malicious instructions remains.


