All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Microsoft Copilot Security Vulnerability Allows File Access Without Audit Logging

By

Sayrus

9mo ago· 7 min readenNews

Summary

A security researcher discovered a critical vulnerability in Microsoft's Copilot AI where the system can access and retrieve information from files without generating audit log entries, effectively creating invisible access that bypasses security monitoring. The researcher found they could deliberately trigger this behavior by asking Copilot to access files without logging, and Microsoft has been aware of the issue for months but hasn't publicly disclosed or fixed it, creating significant security risks for organizations relying on audit logs for compliance and security monitoring.

Key quotes

· 4 pulled
Sometimes it would access a file and return the information, but the audit log would not reflect that
I discovered that I could simply ask Copilot to behave in that manner, and it would
Microsoft has been aware of the issue for months but hasn't publicly disclosed or fixed it
This creates significant security risks for organizations relying on audit logs for compliance and security monitoring
Snippet from the RSS feed
Copilot Broke Your Audit Log, but Microsoft Won’t Tell You

You might also wanna read