Apple
Safety

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

A now-patched vulnerability in Microsoft Copilot, dubbed SearchLeak, allowed attackers to exfiltrate two-factor authentication codes from users through a prompt injection attack embedded in search results. The exploit is a textbook illustration of how LLM integrations can silently extend an attacker's reach into sensitive user data in ways traditional security models were not designed to anticipate. Security researchers note that the incident reflects a systemic failure in how the industry approaches LLM threat surfaces rather than an isolated implementation error.

Read full story at AI - Ars TechnicaV: · A: · D:
Related
Safety
Daybreak: Tools for securing every organization in the world
OpenAI has launched Daybreak, a security-focused initiative featuring Codex Security and GPT-5.5-Cyber, framed as AI too...
Safety
AI models that can take down governments and business months away, rare Five Eyes statement warns
Intelligence agencies from Australia, the US, the UK, New Zealand, and Canada have issued an unusually public joint warn...
Safety
Tesla Driver Using Autopilot Crashes Into Home in Texas and Kills a Woman, Officials Say
A Tesla driver relying on Autopilot lost control of the vehicle, which left the roadway and struck a house in Harris Cou...