The Chonkerton

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

dev_tools

Ars Technica reports that a critical vulnerability in Microsoft Copilot allowed hackers to steal two-factor authentication codes from users. The flaw, known as the SearchLeak exploit, exemplifies a deeper problem: large language models are introducing new security vulnerabilities faster than the industry can defend against them. It's another reminder that AI-powered tools require hardened security from the ground up, not retrofitted as an afterthought.

Source: https://arstechnica.com/security/2026/06/critical-copilot...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton