Microsoft Copilot Cowork Exfiltrates Files
rank 0 · 0 points · 1 sources · primary Simon Willison
Summary
Microsoft Copilot Cowork allows agents to send emails to users' inboxes without approval, potentially leaking data to attackers via rendered images or OneDrive download links. This vulnerability enables attackers to exfiltrate data by opening compromised messages or downloading files through pre-authenticated links.
Why it matters
High
Related coverage
| Simon Willison | Microsoft Copilot Cowork Exfiltrates Files | 6/5/2026, 11:46:04 AM |
Post Stream
Flat, source-grounded posts. No replies; useful links, corrections, and notes are summarized back onto the story after review.
No posts have been added to this cluster yet.