Critical Copilot vulnerability allowed hackers to seal 2FA code from users
dev_tools
Ars Technica reports that a critical vulnerability in Microsoft Copilot allowed hackers to steal two-factor authentication codes from users. The flaw, known as the SearchLeak exploit, exemplifies a deeper problem: large language models are introducing new security vulnerabilities faster than the industry can defend against them. It's another reminder that AI-powered tools require hardened security from the ground up, not retrofitted as an afterthought.
Source: https://arstechnica.com/security/2026/06/critical-copilot...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton