Security
Microsoft patches critical Copilot flaw exposing 2FA codes
A max-critical vulnerability in Microsoft 365 Copilot allowed attackers to extract two-factor authentication codes and other sensitive data from user emails. The flaw, patched on June 11, exploited the AI's inability to distinguish between user instructions and malicious content in third-party data.