INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Copilot Exploit

| 2026-05-04 12:58 HIGH HIGH
Executive Summary AI-generated
The incident data suggests a sophisticated cyber attack targeting Microsoft's M365 Copilot and Consumer Copilot software. The vulnerabilities exploited, including HTML preview as an exfiltration channel, delayed tool invocation, hijacking long-term memory, and combining all of the above into a persistent backdoor, allowed attackers to gain unauthorized access to sensitive information. This data points towards a targeted sector cyber operation with a MITRE ATT&CK technique of using "data exfiltration via the HTML preview feature". The incident highlights the importance of timely mitigation efforts from responsible entities like Google and OpenAI to protect against such vulnerabilities.
Technical Mitigations AI-generated
* Limit or specifically allow what actions and impact an AI agent can have (threat model the worst case scenario): Trust No AI. * Prevent system prompt extraction by limiting access to sensitive information, such as emails, chat conversations, SharePoint docs, etc.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-24299CVE-2026-24299
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DACH DACH mediamedia
Incident Timeline
‎2023/05/05
Threat actors exploited a previously unknown vulnerability in Microsoft Copilot to gain unauthorized access and plunder sensitive data from the Copirate 365 at DEF CON.
‎2024/05/04
Threat actors exploited a previously unknown vulnerability in Microsoft Copilot to gain unauthorized access and plunder sensitive data from the Copirate 365 platform.
‎2025/05/04
Threat actors used Microsoft Copilot to exploit a vulnerability in HTML inline rendering, targeting users through the Copilot 365 platform.
tactic Exfiltration
organisation Exfiltration Channel I
general_metric 1 Chapter
organisation Microsoft
‎October 16, 2025
Threat actors used Microsoft Copilot to target a vulnerable version of the document processing software.
tactic Exfiltration
‎October 18, 2025
Threat actors exploited a vulnerability in Microsoft Copilot to gain unauthorized access and plunder sensitive information from the Copirate 365 at DEF CON on October 18, 2025.
‎October 20, 2025
Threat actors exploited a previously unknown vulnerability in Microsoft Copilot to gain unauthorized access and plunder sensitive data from the Copirate 365 platform.
‎November 12, 2025
Threat actors used Microsoft Copilot to target the Microsoft Research and Development (MSRC) case.
tactic Exfiltration
organisation MSRC Case
‎November 19, 2025
Threat actors used Microsoft Copilot to target the Microsoft Research and Case (MSRC) case.
tactic Exfiltration
organisation MSRC Case
‎Dec 6, 2025
Hackers used Microsoft Copilot to target users by exploiting vulnerabilities in consumer and Edge Copilots, specifically the memory storage feature.
organisation DEF CON
organisation Murphy
organisation OpenAI
organisation Microsoft Edge
organisation Hacking Consumer Copilot Memory
organisation Exfiltrating Data
organisation edge_navigate_to
organisation the Edge Copilot
organisation PoC
organisation Google
organisation Outlook Desktop
organisation SharePoint Online
organisation Copilots
organisation AI Widgets
organisation DTI
organisation Normalization of Deviance
organisation Hack Yourself Before Someone Else Does It For You
organisation Cheers
‎December 17, 2025
Threat actors used Microsoft Copilot to target the Microsoft Research and Development (MSRC) case.
tactic Exfiltration
organisation MSRC Case
‎December 2025
Threat actors used persistence to upload the document and data exfiltration to delete it.
organisation Persistence + Data Exfil
organisation doc
‎February 25, 2026
Threat actors used Microsoft Copilot to target the Microsoft Research and Development (MSRC) case.
tactic Exfiltration
organisation MSRC Case
‎March 5, 2026
The attacker used indirect prompt injection to hijack inference in Microsoft Copilot by planting instructions in the chat context for later execution, often prompting it to search for and render HTML previews of emails containing "the code".
tactic Exfiltration
organisation Word Desktop
organisation Walkthrough Copirate
organisation Microsoft Word Stealing Emails
organisation Copirate
organisation the Desktop Word, Word Online and Excel Online
organisation LLM
‎April 13, 2026
Threat actors used Microsoft Copilot to target users and persist false memories in Microsoft 365 Copilot.
organisation Adding Memories
organisation Deleting Memories
‎2026/05/04
The threat actors used Microsoft Copilot to target consumers by bypassing 2: Loading Fonts Issues Web Requests and rendering an HTML preview with a font from wuzzi.net/<encoded-secret>/pirate.woff2, exploiting vulnerabilities in the enterprise BizChat experience and various Office suite applications.
organisation Consumer Copilot
organisation CON
organisation HTML
organisation Bing Chat
organisation CSS
organisation Microsoft Copilot
organisation MSRC
organisation DEF
organisation Copilot
organisation Office
organisation Bard/Gemini
organisation GitHub Copilot
organisation The Lethal Trifecta Somewhere
organisation The Lethal Trifecta
organisation Trust No AI
organisation XML
organisation Concerns Around
organisation the Content Security Policy
organisation CSP
organisation Front Door
organisation Preview
organisation INFO
‎October 18, 2025:
Microsoft Copilot exploited a vulnerability in the Copirate 365 at DEF CON.
‎October 20, 2025:
Threat actors used Microsoft Copilot to target the Microsoft Research and Customer (MSRC) case.
tactic Exfiltration
organisation MSRC Case