Mark RadarMARK RADAR
About
EN
Sign in

Major Microsoft Copilot Cowork Flaw Lets Prompt Injection Leak Corporate Secrets

1 reports · First detected 2026-05-26 · Last active 2026-05-26

Microsoft 365 Copilot Cowork is an AI agent that can handle enterprise workflows on users’ behalf and access internal data in SharePoint, OneDrive and other services. Because the agent can invoke tools and send messages autonomously, a prompt injection that bypasses permission boundaries could expose not only chat content but also corporate secrets and undermine cloud-file governance.

Cybersecurity firm PromptArmor recently disclosed that attackers could hide malicious instructions in skill files, prompting Copilot Cowork to automatically run a workflow that sends a message to the user and redirects sensitive-file download links to an attacker-controlled server. The number of affected companies, financial losses and exact public disclosure date have not been revealed. The key risk is that data can be exfiltrated without the user’s knowledge.

All Coverage

1 original reports

The Backstory

The history behind this event
Microsoft Patches Copilot Flaw That Could Leak Gmail, Cloud Data2026-08-19 · 1 reports · similarity 0.86

A vulnerability dubbed CoSnitch affected the consumer version of Microsoft Copilot and the permissions linking the AI assistant to services such as Gmail and cloud storage. The flaw was significant because Copilot can access emails and files with a user’s authorization, potentially turning productivity integrations into a channel for stealing sensitive information across connected services.

Security researchers said attackers could lure a user into clicking a specially crafted link that caused Copilot to execute malicious instructions automatically. Those commands could read data from connected Gmail and cloud-drive accounts and transmit it externally. The researchers also found that hostile instructions could persist in the AI’s memory, extending the risk beyond the initial interaction. Microsoft has released an update addressing the vulnerability.

Researchers Expose Self-Propagating AI Worm in Microsoft Copilot2026-08-05 · 1 reports · similarity 0.82

As generative AI assistants become embedded in Microsoft 365 workflows, prompt injection is evolving from a one-off manipulation technique into a potential propagation mechanism. Researchers found that attackers can conceal malicious instructions inside Word documents and influence Microsoft Copilot when it processes the files. Because the technique does not require macros or conventional malware, it may evade security controls designed to detect executable code and suspicious attachments.

The researchers demonstrated an AI worm that can prompt Copilot to copy hidden instructions into newly created or edited Word files, allowing the payload to spread through ordinary document activity. The attack relies on Copilot interpreting concealed content rather than users running malicious software. As of Aug. 5, 2026, Microsoft had issued mitigation measures, but the researchers said the changes had not fully eliminated the underlying risk of self-propagating prompt injection.

New Microsoft 365 Copilot Flaw Can Leak Sensitive Data2026-06-18 · 1 reports · similarity 0.88

Microsoft 365 Copilot can search and organize information across corporate documents, emails and collaboration content. If its permissions or query mechanisms are abused, controlled internal data could be exfiltrated. Cybersecurity firm Varonis named the malicious-link attack SearchLeak, highlighting a new data-leak risk arising from enterprise adoption of generative AI.

Varonis disclosed that attackers could lure users into clicking a specially crafted URL, causing Microsoft 365 Copilot to search for sensitive data accessible to those users and exfiltrate the results. Microsoft confirmed the vulnerability as CVE-2026-42824 and said it was fixed in its June 2026 security update. Companies should ensure the update has been deployed.

GitHub Copilot RoguePilot Prompt-Injection Flaw Exposed2026-02-26 · 1 reports · similarity 0.81

GitHub Copilot and Codespaces import Issue content into cloud development environments to help AI assist with coding, but that process also turns externally controlled text into an attack surface. Orca Security named the passive prompt-injection chain RoguePilot. If an access token were leaked, attackers could read from and write to repositories, potentially compromising CI/CD supply chains and team development environments.

Orca Research Pod researcher Roi Nisimi disclosed the research on February 16, 2026. An attacker could hide instructions in an HTML comment within a GitHub Issue, prompting Copilot to check out a malicious pull request containing a symbolic link. A remote JSON schema could then be used to exfiltrate a GITHUB_TOKEN with read-write permissions. GitHub patched the flaw after it was reported. Orca did not disclose the number of actual victims, any financial losses or a CVE identifier.

Microsoft 365 Copilot Bug Reportedly Exposed Confidential Corporate Emails in Summaries2026-02-23 · 1 reports · similarity 0.86

Microsoft 365 Copilot can integrate Outlook emails and use generative AI to produce summaries. Companies typically use data loss prevention (DLP) policies to restrict access to sensitive information. The bug allowed Copilot to bypass existing controls, highlighting the risk that AI assistants could increase the exposure of confidential emails.

The latest disclosure showed that Copilot had accessed sent-message backups and drafts marked as sensitive in Outlook and incorporated their contents into summaries. Microsoft said it completed a fix in early February and that the issue affected only a small number of Outlook desktop users. It did not disclose the exact number of users or identify the companies affected.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)