Worth Reading – Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks
You kind of have to admire the creativity:
Microsoft Copilot Email Summarization Vulnerability allows an attacker to hijack Copilot’s output by embedding attacker-controlled text in an ordinary email, producing convincing phishing content within the assistant’s trusted summary.
https://cybersecuritynews.com/microsoft-copilot-summarization-vulnerability/
If you can get Copilot to drop a link into the auto-summary, it would be less suspicious than an email sent from outside with a link. That’s probably true. After all, if you trust your AI Summarization tool to summarize the email instead of reading it, why wouldn’t you trust any links it included?
Yet again, blindly trusting your AI tool is a disaster waiting to happen.

Likes
Reposts