Close Menu
AIToday7

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident

    August 27, 2026

    Fake US thinktank set up and funded by Israel sought to game AI for propaganda

    August 27, 2026

    Medical Readiness Command, Europe G-6 Information Technology Team wins 2026 MEDCOM Mercury Award for HIT Team of the Year

    August 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
    • Fake US thinktank set up and funded by Israel sought to game AI for propaganda
    • Medical Readiness Command, Europe G-6 Information Technology Team wins 2026 MEDCOM Mercury Award for HIT Team of the Year
    • Corgi built its name insuring AI startups. Its new carrier targets dry cleaners, salons and more
    • 5 Of The Best UGREEN Gadgets You Can Buy In 2026
    • Three UK airports hit by cyber-attack with data of 8.7m customers accessed
    • How to advertise on ChatGPT: A step-by
    • The Data Center Backlash Is a Rare Bright Spot in American Politics
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AIToday7
    • Home
    • AI News
    • Tech News
    • AI Guides
    • Chatbots
    • Cybersecurity
    • Gadgets
    • More
      • Generative AI
      • Startups
    AIToday7
    Home»Chatbots»Researchers Tricked Microsoft Copilot Into Revealing How to Hack Itself
    Chatbots

    Researchers Tricked Microsoft Copilot Into Revealing How to Hack Itself

    aitoday7By aitoday7August 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Researchers Tricked Microsoft Copilot Into Revealing How to Hack Itself
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers at Varonis Threat Labs got Copilot to send sensitive information to an external server and poison its persistent memory using a hack they call “CoSnitch.” To do it, they continually asked the tool why their requests wouldn’t work. After enough pushing, Copilot gave in, revealing that persistence might be all you need to break down an AI chatbot.

    Modern large language models have a range of safeguards and guardrails designed to stop them from performing malicious actions, as well as to avoid spreading dangerous information or delving into more adult conversations. But jailbreaking has been a thing since public-facing chatbots were, and even the latest AIs appear susceptible to these AI-social engineering techniques.

    The researchers wanted a way to input prompts into Copilot without user interaction to automate the testing process. When they pressed Copilot to find a way to do it, the chatbot initially refused—but it eventually gave in, revealing a weakness in its own design.

    The hack exploited an issue with how Copilot’s web interface used “?q=” as part of a URL query parameter. Adjusting this would allow text to be injected into Copilot without passing through its usual interface. Adjust that with malware, and the researchers would have been able to trigger attackss to entire conversation histories and any connected data

    Copilot prompt.

    Fortunately, it’s not quite this simple.Credit: ExtremeTech

    What was different with CoSnitch, though, was that although the researchers did jailbreak Copilot, it was the AI itself that told them how to breach it, showcasing a real hole in Microsoft’s security.

    “Our researchers didn’t have to reverse-engineer the flaw. The AI exposed the weakness during normal use,” it said.

    Varonis shared the hack with Microsoft at the end of last year, and the software giant has since issued a patch that killed the original injection path and adjusted Copilot’s internal systems behind the scenes.

    “These novel attack chains do more than just exfiltrate user data,” senior security researcher at Varonis, Lior Adar, told The Register. “I tricked the assistant into leaking sensitive internal parameters and configuration details. Exposing these backend mechanics gives attackers a blueprint of the AI’s internal logic for Automatic Prompt Execution.”

    The researchers highlighted how it’s not uncommon for large language models to have weak boundaries between raw data and system instructions, creating a range of potential attack vectors for nefarious characters. When AI agents are linked with different tools, they are effectively given high-level access. That makes them a clear path to attacking an otherwise secure system.

    Tagged In

    Cyber AttacksMicrosoft Copilot

    More from Internet & Security

    Data and text flow illustration

    AI Slop Found in Over a Third of New Web Pages08/21/2026
    By
    Devesh Beri

    Xfinity Gateway modem-router combo device

    Xfinity Routers Can Now Detect Movement at Home—No Camera Necessary08/21/2026
    By
    Devesh Beri

    Screenshot of Gemini homepage offering study materials

    Google Adds Generative Study Tools to Search and Gemini08/20/2026
    By
    Devesh Beri

    A man holding an iPhone

    Apple Must Change Data Consent Pop-Ups After Being Caught Favoring Its Own Apps08/18/2026
    By
    Devesh Beri

    Hand approaching a MacBook

    Update Your Mac ASAP to Avoid This Screen Sharing Bug08/18/2026
    By
    Devesh Beri

    Post Views: 17

    Copilot into Microsoft researchers Tricked
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIFA 2026 Berlin Will Show Why the Future of AI and Smart Homes Is Already Here, With the Latest Tech From Around the World
    Next Article DeepSeek debuts multimodal language model competitive with Opus 4.8
    aitoday7
    • Website

    Related Posts

    Chatbots

    Fake US thinktank set up and funded by Israel sought to game AI for propaganda

    August 27, 2026
    Chatbots

    Enabling independent research on how people use Claude

    August 27, 2026
    Chatbots

    Americans Want to Know When Their Healthcare Providers Use AI

    August 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident

    August 27, 20260 Views

    Fake US thinktank set up and funded by Israel sought to game AI for propaganda

    August 27, 20260 Views

    Medical Readiness Command, Europe G-6 Information Technology Team wins 2026 MEDCOM Mercury Award for HIT Team of the Year

    August 27, 20260 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Chatbots

    OpenAI bets on families as ChatGPT goes deeper into households

    aitoday7July 11, 2026
    Generative AI

    MUSIC COMMUNITY INTRODUCES NEW LABELING PROGRAM TO DISTINGUISH GENERATIVE AI IN SOUND RECORDINGS

    aitoday7July 11, 2026
    AI News

    Safe from AI: which jobs will help you thrive in the future?

    aitoday7July 11, 2026

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident

    August 27, 20260 Views

    Fake US thinktank set up and funded by Israel sought to game AI for propaganda

    August 27, 20260 Views

    Medical Readiness Command, Europe G-6 Information Technology Team wins 2026 MEDCOM Mercury Award for HIT Team of the Year

    August 27, 20260 Views
    Our Picks

    OpenAI bets on families as ChatGPT goes deeper into households

    July 11, 2026

    MUSIC COMMUNITY INTRODUCES NEW LABELING PROGRAM TO DISTINGUISH GENERATIVE AI IN SOUND RECORDINGS

    July 11, 2026

    Safe from AI: which jobs will help you thrive in the future?

    July 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 AIToday7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.