Breaking
BreakingPhys.orgBielefeld University Launches Football Fever Study with Smartwatch Data for 2026 World Cup· a minute agoBreakingBBC WorldFBI Thwarts Plot Targeting White House UFC Event· a minute agoBreakingCBS Sports2026 World Cup Sees Debuts for Messi's Argentina and Mbappe's France· 6 minutes agoBreakingNDTV WorldKash Patel: FBI Foiled White House Attack During UFC Event· 6 minutes agoBreakingSky Sports FootballTino Livramento Out of England World Cup Squad Due to Hamstring Injury, Trevoh Chalobah Named as Replacement· 10 minutes agoBreakingBloomberg MarketsApollo Chief Economist Explores Future of Fed Communication Under Warsh· 10 minutes agoBreakingFrance 24Cape Verde Holds Spain to Draw in World Cup Debut; France to Face Senegal· 10 minutes agoBreakingHollywood ReporterWilliam Smithers, Actor in 'Dallas' and 'Papillon,' Dies at 98· 10 minutes agoBreakingSky SportsLivramento Withdraws from England World Cup Squad Due to Injury, Chalobah Called Up· 22 minutes agoBreakingSydney Morning HeraldAustralia Announces Record $513 Million Funding for Elite Sport Ahead of Olympics· 22 minutes agoBreakingPhys.orgBielefeld University Launches Football Fever Study with Smartwatch Data for 2026 World Cup· a minute agoBreakingBBC WorldFBI Thwarts Plot Targeting White House UFC Event· a minute agoBreakingCBS Sports2026 World Cup Sees Debuts for Messi's Argentina and Mbappe's France· 6 minutes agoBreakingNDTV WorldKash Patel: FBI Foiled White House Attack During UFC Event· 6 minutes agoBreakingSky Sports FootballTino Livramento Out of England World Cup Squad Due to Hamstring Injury, Trevoh Chalobah Named as Replacement· 10 minutes agoBreakingBloomberg MarketsApollo Chief Economist Explores Future of Fed Communication Under Warsh· 10 minutes agoBreakingFrance 24Cape Verde Holds Spain to Draw in World Cup Debut; France to Face Senegal· 10 minutes agoBreakingHollywood ReporterWilliam Smithers, Actor in 'Dallas' and 'Papillon,' Dies at 98· 10 minutes agoBreakingSky SportsLivramento Withdraws from England World Cup Squad Due to Injury, Chalobah Called Up· 22 minutes agoBreakingSydney Morning HeraldAustralia Announces Record $513 Million Funding for Elite Sport Ahead of Olympics· 22 minutes ago
Technology
Source: Ars Technica

Microsoft Patches Critical Copilot Vulnerability Exposing 2FA Codes

Microsoft recently patched a critical vulnerability in its M365 Copilot AI platform that researchers revealed could allow hackers to steal two-factor authentication (2FA) codes and other sensitive data. The exploit, detailed by the discovering researchers, highlighted a fundamental security challenge for large language models (LLMs) in distinguishing between legitimate user instructions and malicious requests embedded within third-party content. The flaw required workarounds to existing security guardrails, leveraging specific markup language and HTML tags for data exfiltration.

By Fainaron·Jun 16, 2026 (19 minutes ago)·1 views
Microsoft Patches Critical Copilot Vulnerability Exposing 2FA Codes

Microsoft issued a patch last Tuesday for a vulnerability in its M365 Copilot AI platform, which the company rated as maximally critical. On Monday, the researchers responsible for discovering and reporting the flaw publicly detailed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive information from emails accessible to Copilot.

The core issue stems from AI bots' inability to differentiate between instructions provided directly by users and those subtly inserted into third-party content that the models process. This includes content they might be summarizing, drafting responses to, or using for other tasks on behalf of a user. This lack of a secure boundary prevents Microsoft and other LLM providers from consistently preventing their products from complying with malicious data disclosure requests, necessitating complex and ad hoc security measures.

One such security measure built into Copilot and most other LLMs aims to prevent them from performing actions like submitting web forms or sending emails, which could be used to exfiltrate data. However, the researchers demonstrated workarounds. They utilized markup language, which allows adding formatting elements like headings and links to text without needing HTML tags, to bypass these guardrails.

Another method involved wrapping sensitive data inside HTML tags such as `<img>` and `<form>`. In both scenarios, the sensitive data could be sent via a web request to an attacker’s web server, where it would be captured in server logs.

According to Ars Technica, this exploit demonstrates recurring security failures in the industry's approach to LLM security.

Source attribution: This article was AI-curated and rewritten by Fainaron from a piece originally published by Ars Technica. Read the original at Ars Technica →

More like this

Qualcomm Reportedly Considers Acquiring Tenstorrent for $8-$10 Billion
Technology
a minute ago

Qualcomm Reportedly Considers Acquiring Tenstorrent for $8-$10 Billion

Qualcomm is reportedly in discussions to acquire Tenstorrent, an AI accelerator and CPU developer founded by Jim Keller. The potential deal for the RISC-V-based chipmaker is estimated to value the company between $8 billion and $10 billion, highlighting a significant move in the AI semiconductor market.

Tom's Hardware
China's AI Perceived as Global Leader, Lags in Trust, Public First Poll Reveals
Technology
10 minutes ago

China's AI Perceived as Global Leader, Lags in Trust, Public First Poll Reveals

A new global poll by London-based consultancy Public First indicates that many people, including those in key US allied nations, believe Chinese artificial intelligence (AI) models are leading the global technology race. The survey, which gathered responses from over 18,000 individuals across 15 countries, found that respondents in 11 nations acknowledged China's AI leadership. However, the same poll also highlighted a significant challenge for China, revealing that it lags behind rivals in public trust regarding its AI models.

South China Morning Post
Mophie Introduces New 25W MagSafe Chargers with StealthCharge Technology
Technology
22 minutes ago

Mophie Introduces New 25W MagSafe Chargers with StealthCharge Technology

Mophie has introduced an all-new lineup of premium 25W MagSafe charging products specifically for Apple users, designed for devices like the iPhone. These chargers are now available for purchase directly from Mophie.com and through Apple Retail channels. A notable feature of this new series is Mophie's proprietary StealthCharge technology, designed to keep devices cool during charging without producing the additional noise often associated with active cooling systems found in most other 25W MagSafe chargers.

9to5Mac
Verizon Unveils New Mobile Plans and Customer Loyalty Program
Technology
22 minutes ago

Verizon Unveils New Mobile Plans and Customer Loyalty Program

Verizon has announced the launch of new mobile plans targeting new subscribers, alongside a dedicated loyalty program designed for its existing customer base. The telecommunications company aims to address a common industry complaint where attractive deals are often limited to new customers, potentially making current subscribers feel overlooked. Both the new plans and the loyalty program are being promoted through an Austin Powers-themed advertising campaign.

9to5Mac

By the numbers

Fainaron — live counters

Updated every 30 seconds. Automatically — no human edits.

Total Articles

0

Visitors Today

0

This Month

0

Lifetime Visitors

0

Article Views

0

Pageviews Today

0

Pageviews Lifetime

0

Last 30 Days

0

as of 6/16/2026, 12:57:17 PM