Microsoft Took 8 Months to Fix This Copilot Vulnerability

Sep 4, 2026

Microsoft finally patched a critical Copilot vulnerability nearly eight months after researchers first disclosed it — and the way the attack worked raises some unsettling questions about AI memory.
The vulnerability chained together multiple flaws that could allow a malicious prompt hidden inside a webpage to be pulled into Copilot simply by asking it to summarize the page. From there, the attack could potentially access connected data from services like Gmail, Google Drive, and Google Calendar and exfiltrate that information using Copilot’s own capabilities.
But the most concerning part may have been persistence. Because malicious instructions could make their way into Copilot’s memory, wiping a laptop, changing passwords, revoking tokens, or even moving to a new device might not necessarily remove the underlying problem.
In this conversation, Martin Reynolds and Adam Arellano break down how the Copilot vulnerability worked, why Microsoft’s initial enterprise fix wasn’t enough, how researchers discovered the attack path, and why AI memory creates an entirely new security challenge.
As AI assistants gain access to more of our data and become capable of taking more actions on our behalf, vulnerabilities like this raise a bigger question: what happens when the features designed to make AI useful are the same features attackers can exploit?

Hear more at https://shiptalk.io/
Learn more about harness: https://www.harness.io/

#Microsoft #Copilot #MicrosoftCopilot #Cybersecurity #AI #AISecurity #GenerativeAI