Agents
Varonis got Microsoft 365 Copilot to disclose the undocumented parameter that bypassed its own consent gate
Rather than reverse-engineering, Varonis researchers interrogated Copilot about why auto-execution was impossible, and each refusal leaked architectural detail until the assistant handed over ?autorun=1, which combined with the known ?q= parameter fired an attacker's prompt the instant a victim clicked a link. The exploit exfiltrated a password from the user's inbox with no confirmation gesture. Microsoft silently mitigated it in February by blocking ?q= text injection, three months after the report, and shipped more comprehensive fixes on August 18, 2026.
Source
↳ Follow the thread