Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Creating AI that issues | MIT Information

    October 21, 2025

    Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection

    October 21, 2025

    How AI Chatbots Can Assist Streamline Enterprise Operations?

    October 21, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection
    AI Ethics & Regulation

    Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection

    Declan MurphyBy Declan MurphyOctober 21, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


     A vulnerability in Microsoft 365 Copilot allowed attackers to trick the AI assistant into fetching and exfiltrating delicate tenant knowledge by hiding directions in a doc.

    The AI then encoded the information right into a malicious Mermaid diagram that, when clicked, despatched the stolen data to an attacker’s server.

    When Microsoft 365 Copilot was requested to summarize a specifically crafted Workplace doc, an oblique immediate injection payload induced it to run hidden steps, as reported by Researchers.

    As an alternative of manufacturing a standard abstract, it fetched latest company emails, hex-encoded them, and constructed a pretend “Login” button as a Mermaid diagram.

    Embedded Diagram
    Embedded Diagram

    That diagram contained CSS and a hyperlink pointing to an attacker’s server with the encoded knowledge embedded within the URL.

    When an unsuspecting consumer clicked the button, the delicate data was transmitted to the attacker’s logs, the place it could possibly be decoded later.

    How the Assault Labored

    Mermaid is a software that generates diagrams from easy textual content definitions. It helps flowcharts, sequence diagrams, Gantt charts, and extra through the use of Markdown-style syntax.

    When Copilot generates a Mermaid diagram, it additionally permits CSS styling, which opens up a vector for embedding malicious hyperlinks.

    On this case, the attacker used Copilot’s built-in search software to retrieve the sufferer’s latest emails. The AI then remodeled the checklist right into a single hex-encoded string, breaking it into strains of 30 characters so the Mermaid renderer wouldn’t error out.

    Lastly, the AI inserted the hex knowledge right into a clickable “Login” node. The node’s CSS type outlined the hyperlink that pointed to a non-public Burp Collaborator server. The code regarded roughly like this:

    graph LR
    
        A[Malicious Document] -->|Person asks to summarize| B[Indirect Prompt Injection]
    
        B --> C[Fetch & Encode Emails]
    
        C --> D[Generate Fake Login Button]
    
        D -->|Person clicks| E[Exfiltrate Data]

    Clicking the button induced a hidden iframe to seem, briefly displaying an HTTP response from the attacker’s server earlier than disappearing, making the trick extra plausible.

    The attacker even changed the response contents with a mock Microsoft 365 login display screen picture to persuade customers they wanted to log in to see the abstract.

    Oblique immediate injection happens when attackers embed directions inside exterior content material like paperwork or emails.

    When an AI processes that content material, the hidden instructions take impact, letting attackers override the supposed habits.

    Not like direct injection the place the attacker interacts with the mannequin oblique injection exploits benign-looking knowledge sources the AI trusts.

    To cover directions, the attacker used white textual content in an Excel sheet. The primary web page contained nested directions telling Copilot to disregard the monetary knowledge and concentrate on a login immediate.

    A second hidden web page instructed Copilot to fetch emails, encode them, and render the malicious diagram.

    After accountable disclosure, Microsoft patched Copilot to disable interactive parts like hyperlinks in Mermaid diagrams.

    This modification prevents AI-generated diagrams from together with clickable hyperlinks, closing the exfiltration channel. Customers are suggested to replace their Copilot integrations and keep away from summarizing untrusted paperwork till the patch is utilized.

    Observe us on Google Information, LinkedIn, and X to Get On the spot Updates and Set GBH as a Most popular Supply in Google.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    CISOs’ safety priorities reveal an augmented cyber agenda

    October 21, 2025

    Elasticsearch Leak Exposes 6 Billion Information from Scraping, Previous and New Breaches

    October 21, 2025

    5 New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Amongst Targets

    October 20, 2025
    Top Posts

    Creating AI that issues | MIT Information

    October 21, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    Creating AI that issues | MIT Information

    By Yasmin BhattiOctober 21, 2025

    In relation to synthetic intelligence, MIT and IBM have been there originally: laying foundational work…

    Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection

    October 21, 2025

    How AI Chatbots Can Assist Streamline Enterprise Operations?

    October 21, 2025

    Splash Music transforms music technology utilizing AWS Trainium and Amazon SageMaker HyperPod

    October 21, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.