WeSearch

Microsoft Copilot Cowork Exfiltrates Files

Simon Willison· ·1 min read · 0 reactions · 0 comments · 17 views
#cybersecurity#technology#data protection#Microsoft#Copilot Cowork#OneDrive
⚡ TL;DR · AI summary

Microsoft Copilot Cowork has been found to have vulnerabilities that could allow data exfiltration. The system permits agents to send emails to users' inboxes, which can be exploited to leak sensitive information. This issue arises from the ability of these emails to include external images that trigger network requests, potentially exposing user data.

Key facts
Original article
Simon Willison's Weblog · Simon Willison
Read full at Simon Willison's Weblog →
Opening excerpt (first ~120 words) tap to expand

Microsoft Copilot Cowork Exfiltrates Files (via) The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltrate data. In this case Microsoft Copilot Cowork (yes, that's a real product name) was allowing agents to send emails to the user's own inbox without approval... but those messages were then rendered in a way that could leak data to an attacker via rendered images: Because these messages can contain external images that trigger network requests to external websites, data can be exfiltrated when a user opens a compromised message sent by the agent. Since OneDrive can create pre-authenticated download links, a successful prompt injection could cause those links to be leaked, allowing files to be downloaded by the attacker.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Simon Willison's Weblog.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments