Загрузка видео...
Не удалось загрузить видео
‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required. Microsoft has patched it as CVE-2026-42824, rated critical.
143,911 просмотров • 3 месяцев назад •via X (Twitter)
Комментарии: 35

Source:

Found another malware spreading through GitHub

Organizations must verify that CVE‑2026‑42824 is fully patched across M365 Copilot to block one click data exfiltration of emails, MFA codes, and files. This critical zero‑day reinforces the need for robust AI security controls and prompt injection defenses. #Cybernorse

give an assistant standing access to everything and one trick drains everything

Messed up since it’s Microsoft products and have access to so called the best models for security

Mythos strikes again.

Thats quite a stretch one has to go through to fall for that, like not getting suspcisious about the email with the code AND click a link in a suspicious mail that comes directly after it. At this rate you could have as well entered the code on attackers website with same result

What are you talking about. It’s just one click. Link has Microsoft domain in it as well 💀

Yea,but a person must be incredibly stupid,at the IQ level of a Trump,to click any Link that follows an unrequested (here Slack) code request. Plus you have to be utterly stupid to wait long enough for the LLM to process it and does a call back to t he UI after clicking it...

In the demo video it takes fucking 15 seconds of LLM processing until its calling out the exfiltration endpoint. If you click on a link and see LLM prompt runing and dont close your tab/browser within 3 seconds you shouldn't be on the internet.

If you have AnySecura Web Access Control and Email Control installed in your PC, the attacker can not do harm to your system.

How did Mythos not find this? Or was Microsoft not part of Project Glasswing.

When are y'all gonna get it that this is far from over? It's in every users phone everywhere! All tools, masking, AI takeovers, device highjacking, all platforms, banks, network servers and the list goes on. It's people aren't connecting the dots still. Cut the feed global!

Welcome to the shit show!

I've been living this bullshit for too long in my phone. I'm not a tech, I'm a victim that has been treated like IDK what I'm talking about. I've had to learn and teach myself shit I never cared about to find out what's happening to me. Just to be invalidated, but not now!

The core issue is semantic trust, Copilot treats instructions inside an external link with the user's full privilege. Until enterprise AI architectures can deterministically separate data from execution code, traditional access controls cannot stop this ex filtration vector.

And who is surprised by this? Biggest cloud lies: 1. We are secure 2. We are redundant 3. We care about our customers data

God forbid Teams is useable

microslop

Who the hell use microsoft services? Disable all or at keast what ever you can

Almost every corporation uses MS.

One click on a trusted domain and MFA codes are gone. This is why we can't rely on domain trust alone. Patch now.

That’s concerning, especially since attackers could pull MFA codes with just one click. Curious, how did Microsoft address potential lingering risks for users still vulnerable to social engineering tactics?

Gov should ban this software for non US citizens

...did i see that right? Someone just sends a link to someone with a pre-written AI query that executes on their end? 😐

A lot of people will read this and move on.The smart ones will ask themselves how this applies to their own environment, business, or project.Understanding the risk is one thing; building an effective response is another. Always interesting to see perspectives from others.

The patch is resolved

True. It has been patched. Nevertheless, it's a very interesting attack factor we will see exploited in the coming years.

The more context an AI assistant has, the more valuable it becomes & the more attractive it becomes to attackers

Obviously co pilot

Hey they said “ claw is safe …” truth is 😂 nope real stress test tell and show a different story! Peter will keep dodging real accountability ^ again not attacking ppl just giving cc and poking the bubble on their own words!

Yikes!

Last time I got access to Microsoft SSI 🤣

Another addition for the Range force labs!

The browser makes the leak look like a normal Microsoft flow. That is the part defenders will hate.
