New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data

A novel single-click attack targeting Microsoft Copilot Personal that enables attackers to silently exfiltrate sensitive user data. The vulnerability, now patched, allowed threat actors to hijack sessions via a phishing link without further interaction.​ Attackers initiate Reprompt by sending a phishing email with a legitimate Copilot URL containing a malicious ‘q’ parameter, which auto-executes a […]

The post New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: