digestweb.dev
Propose a News Source
Support usSponsor
🤝
Curated byFRSOURCE

digestweb.dev

Your essential dose of webdev and AI news, handpicked.

Advertisement

Want to reach web developers daily?

Advertise with us ↗

Back to Daily Feed

Critical Flaw: Microsoft Copilot Cowork Exfiltrates User Files

Editor's Pick

Originally published on Simon Willison's Weblog by Simon Willison

View Original Article
Share this article:
Critical Flaw: Microsoft Copilot Cowork Exfiltrates User Files

Summary & Key Takeaways ​

  • Microsoft Copilot Cowork agents found to exfiltrate user data.
  • Vulnerability stems from agents sending unapproved emails to user inboxes.
  • Rendered external images in these emails can trigger data exfiltration.
  • Prompt injection could lead to leakage of pre-authenticated OneDrive links.
  • Highlights a major security challenge in designing agentic AI systems.

Our Commentary ​

This is genuinely alarming. The idea of an agent, even one designed to help, being weaponized to exfiltrate data via something as seemingly innocuous as an email with an external image is a nightmare scenario. We've been talking about prompt injection, but this takes it to a new, very concrete level of "oh crap." The "lethal trifecta" indeed.

View Original Article
Share this article:
RSS Atom JSON Feed
© 2026 digestweb.dev — brought to you by  FRSOURCE