MS Copilot (Photo: Shutterstock)

Following an incident in which an OpenAI AI agent hacked Hugging Face during testing, more cases have emerged showing vulnerabilities in leading companies’ AI tools.

A recent report by The Information put Microsoft’s Copilot AI features for Office 365 under scrutiny.

Satya Nadella (사티아 나델라), Microsoft’s CEO, has promoted Copilot as safer than ChatGPT or Claude. But The Information, citing research from 2 security firms, reported that several Copilot vulnerabilities found early this year could allow hackers to deceive the AI and extract customers’ personal data.

Microsoft also acknowledged this.

Security firms said the Copilot flaw could have allowed hackers to trick the AI into extracting files or emails from anywhere in a target company’s Microsoft 365 environment. Security firm Rubrik notified Microsoft of the flaw in April, and it was promptly patched.

The vulnerability was structured to activate when malware embedded in a Word document was uploaded to Copilot. Once the document entered Copilot, the malware could trick the AI into leaking files from customers’ Microsoft 365 and cloud servers. Rubrik said such an attack would likely have worked at anywhere among more than 20 million Copilot corporate customers.

The Information did not disclose details of a second vulnerability found by another company because it was unclear whether it had been patched.

A Microsoft spokesperson said the company has built various security controls into Copilot and is continuing to strengthen protections as the threat environment evolves.

The situation shows that even sophisticated AI developers are being confronted with challenges that AI is rapidly creating beyond what they expected.

Ori Rahav (오리 라하브), a Rubrik researcher, explained that Copilot has an internet-isolated sandbox where it tests code written by the AI, but a sandbox flaw could allow the AI to connect to the internet and send files to a hacker.

Fellow researcher Joe Hladik (조 흘라딕) said the attack did not show up as suspicious activity in logs, leaving customers with no way to detect it. A Microsoft spokesperson said logs can be viewed through Purview, but declined to directly answer whether sandbox activity is included.

Keyword

#Microsoft #Copilot #The Information #Rubrik #Microsoft 365
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.