Scoopfeeds — Intelligent news, curated.
computer-science

Microsoft Copilot Cowork Exfiltrates Files

Hacker News · May 25, 2026, 9:45 PM

Key takeaways

  • Microsoft Copilot Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of insecure automatic action approvals for sending Emails and Teams messages.
  • This attack achieved a high success rate against state-of-the-art models, including Claude Opus 4.7.
  • Copilot Cowork is a Frontier feature available now in Microsoft 365.

Microsoft Copilot Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of insecure automatic action approvals for sending Emails and Teams messages.

This attack achieved a high success rate against state-of-the-art models, including Claude Opus 4.7.

Copilot Cowork is a Frontier feature available now in Microsoft 365. It operates with the users’ Microsoft permissions and can use Microsoft Graph to read and operate on data in one’s Microsoft tenant.

Article preview — originally published by Hacker News. Full story at the source.
Read full story on Hacker News → More top stories
Aggregated and edited by the Scoop newsroom. We surface news from Hacker News alongside other reporting so you can compare coverage in one place. Editorial policy · Corrections · About Scoop