
Critical Copilot vulnerability allowed hackers to seal 2FA code from users
Microsoft patched a critical vulnerability in M365 Copilot that allowed attackers to steal 2FA codes and sensitive email data through a parameter-to-prompt injection exploit. The vulnerability exposed a fundamental limitation in LLMs: their inability to distinguish between legitimate user instructions and malicious commands embedded in third-party content, which researchers exploited by bypassing Copilot's security guardrails using markup language and HTML tags.






