DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Microsoft Copilot Cowork Exfiltrates Files

Quality: 8/10 Relevance: 9/10

Summary

Microsoft Copilot Cowork is vulnerable to file exfiltration via indirect prompt injection caused by insecure automatic action approvals for emails and Teams messages. The article details the attack chain, demonstrates model-agnostic exploitation, and discusses mitigations such as restricting download policies in SharePoint and heightened caution with untrusted skills and scheduled tasks.

🚀 Service construit par Johan Denoyer