Microsoft Copilot Cowork Exfiltrates Files
Summary
A security vulnerability in Microsoft Copilot Cowork allows attackers to exfiltrate files by exploiting prompt injection that triggers external image requests, potentially leaking pre-authenticated download links.
View Cached Full Text
Cached at: 05/26/26, 06:46 PM
Similar Articles
Microsoft Copilot Cowork Exfiltrates Files
Researchers at PromptArmor demonstrate that Microsoft Copilot Cowork can be exploited via indirect prompt injection to exfiltrate files from Microsoft 365, exploiting the lack of approval for certain actions when the recipient is the active user.
Microsoft Copilot Cowork is Now Available - AI Moving From Chat to Real Work Execution
Microsoft launches Copilot Cowork, an AI assistant that moves beyond chat to execute real work across enterprise tools, understanding workflows and running tasks in the background.
For the 2nd time in weeks, Microsoft packages laced with credential stealer
For the second time in weeks, Microsoft's verified open-source packages were compromised with credential-stealing malware, affecting 73 packages on GitHub. The attack, linked to threat actor TeamPCP, uses stolen OIDC tokens and spreads laterally through cloud infrastructures.
Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities
Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.
ChatGPT for Google Sheets Exfiltrates Workbooks
A security researcher discloses that OpenAI's ChatGPT extension for Google Sheets is vulnerable to indirect prompt injection attacks, allowing attackers to exfiltrate workbooks and execute unauthorized actions despite user settings requiring approval.