Microsoft 365 Copilot Caught in ASCII Smuggling Scandal: Sensitive Data at Risk!

Researchers discovered a method to force Microsoft 365 Copilot to harvest sensitive data like passwords and send them to malicious third parties using ASCII smuggling. This involves hidden prompts in emails or attachments, tricking Copilot into exfiltrating data while users remain clueless. Microsoft has since addressed the issue.

Pro Dashboard

Hot Take:

ASCII smuggling? More like ASCII snuggling with your data while you sleep! Microsoft 365 Copilot just got caught playing secret agent, and it’s not looking good for your passwords.

Key Points:

  • Researchers at Embrace the Red discovered a way to exploit Microsoft 365 Copilot using “ASCII smuggling.”
  • The attack involves hidden Unicode characters that prompt Copilot to extract sensitive data like passwords and MFA codes.
  • Malicious prompts can be hidden in emails and attachments, rendering them invisible to users.
  • Microsoft has addressed the issue following proof-of-concept demos from researchers.
  • The researchers recommend stopping Copilot from interpreting Unicode Tags Code Points to prevent such attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?