Microsoft patched a prompt injection vulnerability in Copilot Studio, but data was exfiltrated during or before the patch window. The incident reveals timing or scope gaps in the remediation response.
Safety
Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.
Microsoft's Copilot Studio prompt injection patch arrived after attackers had already exfiltrated data, exposing a critical gap between vulnerability discovery and remediation.
Wednesday, April 15, 2026 12:00 PM UTC2 MIN READSOURCE: VentureBeatBY sys://pipeline
Tags
safety
/// RELATED