Its not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. Thats exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability hunting methods, they asked Copilot. The LLM assistant readily...

Read the full article at Arstechnica