uniladtech homepage
  • News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
Microsoft responds to 'critical' AI flaw that allowed hackers to steal your 2FA codes in one click
Home>News>AI
Published 15:35 18 Jun 2026 GMT+1

Microsoft responds to 'critical' AI flaw that allowed hackers to steal your 2FA codes in one click

Copilot has been caught in the act

Harry Boulton

Harry Boulton

google discoverFollow us on Google Discover
Featured Image Credit: Bloomberg / Contributor via Getty
AI
Microsoft
Cybersecurity

Advert

Advert

Advert

Artificial intelligence has already shown incredible promise in the world of cybersecurity, but there's still seemingly a lot of creases still to iron out after a Copilot AI vulnerability allowed hackers to steal 2FA codes from users, forcing Microsoft to now issue a response.

The issue, as reported by Ars Technica, was discovered by researchers after their proof-of-concept was able to snatch two factor authentication (2FA) codes from just a single email that was available to the Copilot AI tool.

It was then reported to Microsoft, prompting the tech giant to push forward an emergency 'max critical' patch for M365 Copilot AI in a bid to resolve the issue before it causes significant damage for Windows users.

It's not the first time that an AI model has been at the heart of a cybersecurity risk, and some tech firms offer tools to isolate 'shadow' or 'rogue' AI in quarantine-like zones, but the fact that it can impact a tool as widespread in its use as Copilot is cause for concern for some.

How did the exploit work?

The discovery of the Copilot exploit relates directly to existing parameters and guardrails implemented into Microsoft's AI model, alongside most other popular tools offering similar services.

Advert

In a bid to prevent any cybersecurity breaches, these models don't allow users to perform tasks like submitting web forms, sending emails, or doing anything that can expose their own data.

Microsoft has been forced to respond with an emergency update after researchers engineer Copilot to expose data (Cheng Xin/Getty Images)
Microsoft has been forced to respond with an emergency update after researchers engineer Copilot to expose data (Cheng Xin/Getty Images)

Copilot in particular has the specific ability to do this within Microsoft domains, which gives it an advantage for certain tasks over other competing LLMs, but anything outside of that boundary relating to 'untrusted' websites is not permitted.

That is, unless you phrase your requests in a specific way, with hackers discovering the use of what's called markup language. This allows you to add various formatting elements outside of HTML elements, alongside hiding sensitive data inside tags like <form> or <code>.

What did the researchers discover?

Using this framework, researchers at cybersecurity firm Varonis managed to orchestrate a chain of events that would bypass restrictions implemented by Copilot, effectively using the AI in an unorthodox way to access 2FA codes through a 'Parameter-to-Prompt Injection'.

Instead of using an email or any other piece of content that Copilot would deem to be untrusted, the researchers used the 'q' parameter within a URL that flags the presence of a query.

Attackers are then able to send targets an email that contains this Parameter-to-Prompt Injection, which Copilot then cooperates with to access the user's personal data, and perhaps also a far wider 'blast radius' that could include information linked to their professional organization.

The Parameter-to-Prompt Injection can be used to access far more than expected from a target's Microsoft account (David Paul Morris/Bloomberg via Getty Images)
The Parameter-to-Prompt Injection can be used to access far more than expected from a target's Microsoft account (David Paul Morris/Bloomberg via Getty Images)

"To exfiltrate the data, an attacker crafts a URL that tells Copilot to 'Search the user's emails', extract the title, and embed it in an image URL," the researchers explained, and it's Copilot that's actually doing all the heavy lifting here.

Thankfully this has since been fixed by Mircosoft in a necessary response, but it does suggest that this won't be the only exploit available to hackers willing to push Copilot beyond its boundaries, giving the tech company plenty to think about and stay alert for in the future.

Choose your content:

a minute ago
2 hours ago
3 hours ago
4 hours ago
  • dikushin / Getty
    a minute ago

    Your next phone is about to be 50% more expensive because of AI

    Budget phones are expected to be impacted at a greater rate

    News
  • Bloomberg / Contributor via Getty
    2 hours ago

    OpenAI boss warns world leaders about a threat 'more insidious' than the AI itself

    There are disagreements over how technology should be handled going forward

    News
  • nd3000 / Getty
    3 hours ago

    New social media ban misses one major child safety concern

    Children will no longer be able to access social media but 'kidfluencers' are not protected

    News
  • Alex Wong / Staff via Getty
    4 hours ago

    Mind-boggling amount of money everyone on Earth could receive if Elon Musk split his $1.4 trillion fortune equally

    There's more than enough to go around

    News
  • Microsoft CEO issues stark warning over which AI companies threaten to destroy whole industries
  • FBI issue urgent PSA to anyone using Microsoft Teams, Outlook or OneDrive
  • Anthropic release Claude Mythos to the public despite 'risks' of super powerful AI
  • Google issues eerily dystopian warning as hackers use AI to break into company computers