uniladtech homepage
  • News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
Microsoft responds to 'critical' AI flaw that allowed hackers to steal your 2FA codes in one click
Home>News>AI
Published 15:35 18 Jun 2026 GMT+1

Microsoft responds to 'critical' AI flaw that allowed hackers to steal your 2FA codes in one click

Copilot has been caught in the act

Harry Boulton

Harry Boulton

google discoverFollow us on Google Discover
Featured Image Credit: Bloomberg / Contributor via Getty
AI
Microsoft
Cybersecurity

Advert

Advert

Advert

Artificial intelligence has already shown incredible promise in the world of cybersecurity, but there's still seemingly a lot of creases still to iron out after a Copilot AI vulnerability allowed hackers to steal 2FA codes from users, forcing Microsoft to now issue a response.

The issue, as reported by Ars Technica, was discovered by researchers after their proof-of-concept was able to snatch two factor authentication (2FA) codes from just a single email that was available to the Copilot AI tool.

It was then reported to Microsoft, prompting the tech giant to push forward an emergency 'max critical' patch for M365 Copilot AI in a bid to resolve the issue before it causes significant damage for Windows users.

It's not the first time that an AI model has been at the heart of a cybersecurity risk, and some tech firms offer tools to isolate 'shadow' or 'rogue' AI in quarantine-like zones, but the fact that it can impact a tool as widespread in its use as Copilot is cause for concern for some.

How did the exploit work?

The discovery of the Copilot exploit relates directly to existing parameters and guardrails implemented into Microsoft's AI model, alongside most other popular tools offering similar services.

Advert

In a bid to prevent any cybersecurity breaches, these models don't allow users to perform tasks like submitting web forms, sending emails, or doing anything that can expose their own data.

Microsoft has been forced to respond with an emergency update after researchers engineer Copilot to expose data (Cheng Xin/Getty Images)
Microsoft has been forced to respond with an emergency update after researchers engineer Copilot to expose data (Cheng Xin/Getty Images)

Copilot in particular has the specific ability to do this within Microsoft domains, which gives it an advantage for certain tasks over other competing LLMs, but anything outside of that boundary relating to 'untrusted' websites is not permitted.

That is, unless you phrase your requests in a specific way, with hackers discovering the use of what's called markup language. This allows you to add various formatting elements outside of HTML elements, alongside hiding sensitive data inside tags like <form> or <code>.

What did the researchers discover?

Using this framework, researchers at cybersecurity firm Varonis managed to orchestrate a chain of events that would bypass restrictions implemented by Copilot, effectively using the AI in an unorthodox way to access 2FA codes through a 'Parameter-to-Prompt Injection'.

Instead of using an email or any other piece of content that Copilot would deem to be untrusted, the researchers used the 'q' parameter within a URL that flags the presence of a query.

Attackers are then able to send targets an email that contains this Parameter-to-Prompt Injection, which Copilot then cooperates with to access the user's personal data, and perhaps also a far wider 'blast radius' that could include information linked to their professional organization.

The Parameter-to-Prompt Injection can be used to access far more than expected from a target's Microsoft account (David Paul Morris/Bloomberg via Getty Images)
The Parameter-to-Prompt Injection can be used to access far more than expected from a target's Microsoft account (David Paul Morris/Bloomberg via Getty Images)

"To exfiltrate the data, an attacker crafts a URL that tells Copilot to 'Search the user's emails', extract the title, and embed it in an image URL," the researchers explained, and it's Copilot that's actually doing all the heavy lifting here.

Thankfully this has since been fixed by Mircosoft in a necessary response, but it does suggest that this won't be the only exploit available to hackers willing to push Copilot beyond its boundaries, giving the tech company plenty to think about and stay alert for in the future.

Choose your content:

a day ago
  • Patricio Nahuelhual / Getty
    a day ago

    Exactly what happens to your body when you eat heavily burnt food as cancer researcher warns against consuming

    Charring your meals can actually have an unexpected consequence

    Science
  • Chesnot/Getty Images
    a day ago

    Jeff Bezos slams Washington Post business staff as 'terrible' in new report

    Jeff Bezos bought the newspaper back in 2013

    News
  • Bloomberg / Contributor / Getty
    a day ago

    Crypto billionaire warns AI is about to trigger a $527B banking collapse 'bigger than 2008'

    Investment into AI is causing prominent cryptocurrencies to crumble under pressure

    News
  • Anna Moneymaker / Staff / Getty
    a day ago

    OpenAI's confidential financials leak to show $21,000,000,000 in losses

    The tech giant's total expenses climbed from $12.48 billion in 2024 to $34 billion in 2025

    News
  • Microsoft CEO issues stark warning over which AI companies threaten to destroy whole industries
  • FBI issue urgent PSA to anyone using Microsoft Teams, Outlook or OneDrive
  • Anthropic release Claude Mythos to the public despite 'risks' of super powerful AI
  • Google issues eerily dystopian warning as hackers use AI to break into company computers