Microsoft’s Copilot for M365 has a significant vulnerability that allows users to access files without leaving an audit log entry, posing serious security and compliance risks. Despite fixing the issue, Microsoft has chosen not to inform customers or disclose the vulnerability publicly, raising concerns about their transparency and responsibility regarding security practices. The article details the author’s frustrating experience reporting the vulnerability and highlights the implications for organizations relying on accurate audit logs.
A recently discovered zero-click vulnerability in Microsoft 365 Copilot could potentially expose sensitive user data without any interaction required from the user. This flaw highlights significant security concerns regarding AI integration in enterprise services, prompting calls for immediate remediation measures from Microsoft.