News Desk 2024: Hacking Microsoft Copilot Is Scary Easy

Share This Post

Microsoft Copilot is rapidly becoming the go-to artificial intelligence productivity assistant across some of the largest enterprises in the world, but researcher Michael Bargury, chief technology officer with Zenity, warns the new technology poses some distinct cybersecurity concerns.

Bargury isn’t down on Copilot, quite the contrary. He’s found the technology invaluable in his own day-to-day work, he explained to Dark Reading. But based on Copilot’s visibility deep into the enterprise, including emails, messaging applications, and much more — which is precisely what makes it so valuable for users — also makes it an alluring target for malicious actors.

“It has access to your emails, your calendar, your Teams messages, all of your files, and if you bring in plug-ins it can actually work on your behalf,” Bargury explained. “It has access to everything you have access to, even the things you write to yourself.”

Through his research, Bargury was able to demonstrate how to take over Microsoft Copilot by sending a single email.

“I can get Copilot to tell you whatever I want it to tell you,” he added.

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt97022d0629896e29/66ccc346d2a5521a6ed2aaa4/Michael_Bargury_News_Desk.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.