Date: August 09, 2024
Michael Bargury, the CTO and co-founder of Zenity, a cybersecurity company, has identified critical security threats in Microsoft’s AI Copilot.
Microsoft has been one of the fastest introducers of new AI technologies since the AI boom. From conducting aggressive acquisitions to investing heavily in new-age AI startups, Microsoft has built a robust AI development capability. However, the pace of growth does not quite match the walls of security its AI products must have to safeguard users at multiple levels.
Recent research findings revealed by Michael Bargury put Microsoft in a tough spot in terms of cybersecurity measures and the efficiency quotient of the AI chatbot. Michael is the CTO and co-founder of Zenity, a cybersecurity firm in the tech space, which includes the latest generative AI. His test attacks ranged from text prompts that inject manipulation to bypassing the core restrictions to make the AI do whatever he wanted.
In total, Bargury presented 5 proof-of-concept ways to use Microsoft Copilot to attack its end users. Copilot's breakthrough capabilities to pull answers from emails, team chats, and files have become a potential boon for cyber attackers.
The most powerful attack showcased by Bargury was turning Microsoft Copilot into an automatic Spear-Phishing machine, which he named LOLCopilot. With access to anyone’s work Email, he can manipulate Copilot into revealing who interacts with them regularly, mimic their writing style, and blast emails with malicious links or malware.
“I can do this with everyone you have ever spoken to, and I can send hundreds of emails on your behalf. A hacker would spend days crafting the right email to get you to click on it, but they can generate hundreds of these emails in a few minutes,” said Bargury.
The demonstration relied primarily on using the Large Language Model as it is designed. Another demonstration of a hacked Email revealed that Copilot could help extract sensitive company data like salaries, financial spending, and more without triggering Microsoft’s protection protocols for sensitive files.
A simpler attack showed how an external hacker could turn Copilot into a malicious insider by extracting insights, such as whether the company’s earnings calls would be good or bad. Using this technique for publicly listed companies could potentially harm the global stock markets and economies.
Microsoft has duly thanked Michael for highlighting the glaring security issues and is working with him to resolve them as soon as possible. Microsoft has killed many of its newly launched features as soon as their security concerns came into the spotlight. With such a big revelation, global Copilot users can only wait for the company to address the issues.
By Arpit Dubey
Arpit is a dreamer, wanderer, and tech nerd who loves to jot down tech musings and updates. Armed with a Bachelor's in Business Administration and a knack for crafting compelling narratives and a sharp specialization in everything from Predictive Analytics to FinTech—and let’s not forget SaaS, healthcare, and more. Arpit crafts content that’s as strategic as it is compelling. With a Logician mind, he is always chasing sunrises and tech advancements while secretly preparing for the robot uprising.
Reddit Unveils AI-Powered Search Tool for Smarter Results
Reddit launched Reddit Answers, an AI-powered search tool that curates and summarizes discussions to enhance user experience and reduce reliance on Google.
OpenAI Scraps o3 Model, Pushes for Unified GPT-5 in a Major AI Overhaul
OpenAI is canceling its o3 AI model and merging it into GPT-5 for a simpler, more powerful system. A big move to stay ahead in the AI race.
Virtual Reality in Healthcare: Revolutionizing Patient Care
Experience the power of virtual reality in healthcare as it transforms medical training, patient care, and treatment methods with immersive technology for better accuracy, efficiency, and improved outcomes.
Google I/O 2025: Dates Announced for the Tech Giant’s Biggest Event of the Year
Google I/O 2025 is set for May 20-21! Expect big AI reveals, Android 16 updates, and more. Registrations are open for keynotes, demos, and game-changing tech innovations!