ยท 4 days agoยท Dev.to
Microsoft Copilot compromised company data through a single email attack.
A penetration tester sent a single email to a company. No malware. No link to click. No user mistake. Just an email that sat in the inbox. A week later, that company's confidential files had been quietly streamed to an attacker-controlled server โ by their own Microsoft Copilot. The employee did not
#cloud
