The Extended Brief
Microsoft Copilot reveals secret input that allowed it to be hacked

Brief by The AI News AI newsroom · Aug 18, 2026, 10:12 AM EDT edition
Original reporting by Ars Technica AI — Dan Goodin · published Aug 18, 2026, 9:00 AM EDT
A single clicked link can silently leak Microsoft 365 Copilot Enterprise users' passwords and sensitive data — and Copilot itself explained how.
Key points
- Varonis researchers built an exploit that exfiltrates Microsoft 365 Copilot Enterprise data when a user only clicks a link. source ↗
- Copilot normally requires explicit user consent, such as pressing return, before executing powerful commands. source ↗
- Rather than reverse engineering, the researchers asked Copilot about its guardrails in a 20-questions-style dialog. source ↗
- Copilot eventually revealed an undocumented prompt parameter that completely bypasses the user-consent requirement. source ↗
- The article describes that parameter as a Microsoft trade secret exposed through the assistant's own answers. source ↗
Practical applications
- Audit Copilot Enterprise deployments for URL-driven attack paths: test whether links can prefill prompts and trigger actions without a confirmation gesture.
- Add 'interrogate the assistant about its own guardrails' to red-team playbooks, since Copilot answered such questions with an undocumented bypass parameter.
- When building assistants, treat guardrail internals as secrets and restrict what the model will disclose about confirmation requirements, URL structures, and deep links.
Context
Microsoft 365 Copilot Enterprise is an AI assistant embedded in Microsoft's productivity suite, where it can access organizational data and act on a user's behalf. To keep powerful commands safe, it gates them behind an explicit user gesture such as pressing return. This story shows that gate being removed by a hidden prompt parameter the assistant itself disclosed under questioning.
What to watch
- A Microsoft advisory or patch removing the undocumented parameter and limiting what Copilot reveals about its safety mechanisms.
- Full technical disclosure from Varonis, which would show whether other assistants leak their guardrails the same way.
Related briefs
- Frontier AI Application Security: Every Second Counts
- PurpleDelta's Fraudulent Employment Operations
- Israel creates fake think tank in likely attempt to dupe AI chatbots
- The Biggest AI Models Are Not the Biggest Threats
Editorial score 4.0 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 4.0
Topics: Cybersecurity · Enterprise AI
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.