🪟 Windows TippsGrok for PC: Using xAI’s Chat Assistant On a Bigger Screen(16.09.2026 um 09:33 Uhr)
🪟 Windows TippsWindows 11 26H2: Release, Neuerungen und wer jetzt handeln muss(16.09.2026 um 09:37 Uhr)
🪟 Windows TippsGoogle Chrome(16.09.2026 um 08:30 Uhr)
🪟 Windows TippsGoogle stopft mehrere kritische Chrome-Lücken(16.09.2026 um 09:24 Uhr)
🪟 Windows TippsKI-Power für eine klare Sprache(16.09.2026 um 08:45 Uhr)
🤖 Android TippsDas Ende einer Ära: Samsung-Nutzer müssen sich umstellen(16.09.2026 um 08:25 Uhr)
🪟 Windows TippsGrok for PC: Using xAI’s Chat Assistant On a Bigger Screen(16.09.2026 um 09:33 Uhr)
🪟 Windows TippsWindows 11 26H2: Release, Neuerungen und wer jetzt handeln muss(16.09.2026 um 09:37 Uhr)
🪟 Windows TippsGoogle Chrome(16.09.2026 um 08:30 Uhr)
🪟 Windows TippsGoogle stopft mehrere kritische Chrome-Lücken(16.09.2026 um 09:24 Uhr)
🪟 Windows TippsKI-Power für eine klare Sprache(16.09.2026 um 08:45 Uhr)
🤖 Android TippsDas Ende einer Ära: Samsung-Nutzer müssen sich umstellen(16.09.2026 um 08:25 Uhr)

📰 IT Security Nachrichten 🕛 vor 1 Jahr 1 Min Lesezeit SECURITY-FEED
0

Microsoft stays mum about M365 Copilot on-demand security bypass

↗ Quelle (go.theregister.com)
🗣️ Stimme:
AI Executive Summary & Key Takeaways
TL;DR
<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p><strong>Microsoft stays mum about M365 Copilot on-demand security bypass</strong> </p>
<p>Microsoft has not notified customers about a recently patched vulnerability in M365 Copilot that allowed malicious insiders to access enterprise file content without leaving traces in corporate audit logs. The issue, discovered by security researcher Zack Korman of Pistachio, could have been exploited by simply asking Copilot to summarize a company file without providing a link. </p>
<p><strong>How the vulnerability worked</strong><br />
The flaw enabled users to bypass security logging by triggering file summaries through Copilot’s semantic indexing—specifically, the Microsoft Graph API—which did not log the interaction when no file link was generated. Korman confirmed the issue on July 4, 2025, and reported it to Microsoft via the MSRC vulnerability portal. Microsoft classified the flaw as an “important” vulnerability (not “critical”) and patched it within days but chose not to inform customers or the public. </p>
<p><strong>Key implications</strong><br />
- <strong>Inaccurate audit logs</strong>: Organizations using Copilot prior to August 18, 2025, risk incomplete audit records, creating compliance and security risks.<br />
- <strong>Ease of exploitation</strong>: Korman noted the vulnerability was trivial to trigger accidentally, as it required no technical expertise.<br />
- <strong>Historical context</strong>: Microsoft began publicly reporting cloud vulnerabilities as CVEs only last year, but this flaw—classified as “important”—was patched without disclosure. </p>
<p><strong>Background on the discovery</strong><br />
The issue was independently demonstrated by Michael Bargury, CTO of Zenity, at Black Hat 2024. He showed how appending caret characters (<code>^</code>) to Copilot prompts could bypass security controls—a technique that Microsoft did not address until Korman’s report last month. </p>
<p><strong>Expert commentary</strong><br />
Sicherheitsforscher Kevin Beaumont highlighted a broader trend: cloud providers like Microsoft have historically withheld disclosures of non-critical vulnerabilities. He urged governments (e.g., DoD, NHS) to mandate transparent reporting of all cloud vulnerabilities as part of contracts: “Extreme pressure from major governments is needed to ensure cloud providers disclose CVEs for customer-facing issues.” </p>
<p><strong>Microsoft’s response</strong><br />
After the article’s publication, Microsoft issued a statement: <em>“We appreciate the researcher sharing their findings with us so we can address the issue to protect customers.”</em> The statement did not clarify whether customers were notified or how the vulnerability was patched. </p>
<p><strong>Why this matters</strong><br />
This incident underscores the growing challenge of balancing rapid security patching with transparency. With Copilot’s widespread adoption in enterprises, even minor vulnerabilities that bypass logging could compromise data integrity and regulatory compliance—especially when organizations rely on audit logs for legal and security oversight. </p>
<p><em>Updated August 21, 2024 (UTC)</em> </p>
<hr />
<p><em>Note: All irrelevant sections (e.g., Amazon, Perplexity, GSA, and the list of cybersecurity terms) have been removed per the instructions. The focus remains strictly on Microsoft’s handling of the M365 Copilot vulnerability, with contextual details sourced directly from the original report.</em></p><!-- END: Dynamically Added Content -->
Automatisch aggregiert durch myDraft RAG Intelligence Suite

Redmond doesn't bother informing customers about some security fixes

Microsoft has chosen not to tell customers about a recently patched vulnerability in M365 Copilot.…

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf go.theregister.com.
↗ Original-Artikel auf go.theregister.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Grok for PC: Using xAI’s Chat Assistant On a Bigger Screen
1 Quelle
Windows 11 26H2: Release, Neuerungen und wer jetzt handeln muss
1 Quelle
WMF-Messerblock mit 7 Teilen kostet bei Amazon aktuell deutlich weniger
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Microsoft stays mum about M365 Copilot on-demand security bypass

Thematisch verwandte Begriffe: Microsoft, stays, about, M365 · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...