Researchers demonstrate SearchLeak prompt injection attack against M365 Copilot Enterprise

According to CSO Online, security researchers developed a proof-of-concept attack called SearchLeak against Microsoft M365 Copilot Enterprise that exploits parameter-to-prompt injection weaknesses to trick employees into clicking malicious search results and leak sensitive corporate data. The attack combined three weaknesses in Copilot Enterprise Search implementation.

Topics

AI securityMicrosoftMicrosoft 365 Copilot

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.