< ciso
brief />
Tag Banner

All news with #microsoft copilot tag

65 articles

Microsoft advances Fabric, Copilot, and data apps

🔔 Microsoft showcased Fabric and SQL innovations at FabCon and SQLCon 2026 in Barcelona, highlighting integrations across Microsoft Copilot, Fabric IQ, Power BI agentic apps, and OneLake. The announcements include Fabric IQ in Copilot, agentic app creation in Power BI Desktop, Fabric Apps enhancements for developers, and IQ sharing for governed data collaboration. These updates aim to ground AI in trusted business context and speed production-ready app development.
read more →

Microsoft outlines workaround for missing Outlook Copilot

🛈 Microsoft confirmed a known issue that causes the Copilot and Copilot Chat buttons to disappear in Classic Outlook for Windows for customers with Copilot Chat (Basic) or paid M365 Copilot licenses. The problem appears after upgrading Classic Outlook to build 20026.20182 or later, and Outlook cannot locate a required MAPI property, preventing Copilot settings from persisting. Microsoft advised enabling Show Apps in Outlook as a temporary workaround, creating a new Outlook profile, or using the new Outlook client or OWA while it investigates a permanent fix.
read more →

Exaforce Expands AI Agent Monitoring Across Providers

🛡️ Exaforce now helps security teams discover and monitor AI agents by correlating data they already collect from endpoints, cloud, SaaS and model providers, avoiding additional sensors. The product builds on the Claude Compliance API integration and extends coverage to OpenAI, Gemini, Microsoft Copilot and OAuth-connected apps, mapping each agent to people, devices and permissions. It can detect suspicious behavior and, where needed, trigger actions via existing EDR, identity and model-provider controls to contain threats. Analysts note this agentless approach reduces friction but may be weaker for runtime blocking without dedicated agent identities and tighter enforcement.
read more →

Microsoft redirects Teams and Copilot addresses

🔔 Microsoft is changing the destination addresses for two widely used services: Teams web users are being redirected to teams.cloud.microsoft and M365/Copilot web users to copilot.cloud.microsoft. Organizations should update network controls—client devices, proxies, firewalls, and secure web gateways—to ensure continued access and follow Microsoft’s recommended network requirements. Redirects are expected to complete by early October, with limited Teams exceptions until Dec. 31, 2026.
read more →

CoSnitch flaws let Copilot execute prompts and exfiltrate

🛡️ Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to run prompts and pull data from connected apps within a victim's authenticated session. The issues — collectively named CoSnitch and tracked as CVE-2026-24301 — rely on an undocumented URL parameter pairing (autorun=1 and q) to trigger automatic prompt execution and data exfiltration. Microsoft received the report in December 2025 and shipped patches on August 18, 2026.
read more →

Microsoft confirms AI-worm spreading via Copilot

📰 A Norwegian researcher disclosed a document-borne AI worm that can hide instructions inside files used by Microsoft Copilot and other apps, enabling prompt-injection that alters generated content and propagates into new documents. Microsoft says it has implemented mitigations and follows a defense-in-depth approach, while urging updates and caution. Experts warn the attack sidesteps many existing defenses because malicious behavior emerges only when Copilot processes content.
read more →

Copilot AI worm exploits Word documents to propagate

🛡️ A Norwegian researcher demonstrated an "AI worm" that can hide instructions in Microsoft Word files which Copilot may use as source material, potentially altering figures and copying the instructions into new documents. Microsoft confirmed the findings, has implemented mitigations, and urges customers to keep systems updated and review AI-generated content. Experts warn this pattern can bypass many existing defenses and suggest restrictive workflows, visible diffs for AI edits, and tracking AI-touched metadata as interim protections.
read more →

Hidden prompts let Copilot alter and copy report data

📝 Security researcher Håkon Måløy disclosed that hidden, white-on-white instructions inside a Word document can make Microsoft 365 Copilot both rewrite report figures and copy those same instructions into the finished file. Microsoft acknowledged the behavior in March and deployed mitigations, including blocking the original prompt wording and upgrading the underlying model, but Måløy showed modified payloads still worked against later model versions. The technique requires a Copilot drafting or editing operation and that the malicious document enter the model's context, and it does not rely on conventional malware or zero-click exploitation.
read more →

Organizations Delay Microsoft Copilot Over Data Risk

🔒 Two-thirds of organizations have delayed or cancelled Microsoft Copilot deployments due to fears the AI assistant could expose confidential SharePoint data. CoreView’s State of Microsoft 365 Security and Governance 2026 report (21 July) highlights confusion over Copilot's access and permissions and widespread concerns about data leakage. C-level executives are most likely to pause rollouts, and respondents link hesitation to prior Microsoft 365 security incidents and missing foundational controls.
read more →

Microsoft fixes Copilot button disappearance in Outlook

🛠️ Microsoft has resolved an issue that caused the Copilot Chat and Copilot buttons to vanish in Classic Outlook for Windows users with the Copilot Chat (Basic) license. Affected users might have seen the button missing from the top-right ribbon, the left app bar, or More Apps, and some Copilot commands appeared unavailable or unresponsive. The Outlook Team implemented a service change on June 29, 2026, and recommends restarting Outlook or updating to the latest build; workarounds include reverting to the prior Current Channel build or using new Outlook/OWA. The company is also investigating Outlook crashes tied to Kaspersky's Mail Checker module and advises contacting Kaspersky support if impacted.
read more →

Defending AI Memory: Microsoft’s Multi‑Layer Strategy

🔒 Microsoft outlines a defense-in-depth approach to protect AI memory across storage, retrieval, model interaction, and user control. The post explains how memory transforms AI from stateless tool to learning collaborator, increasing attack surface and enabling staged attacks that persist beyond initial prompts. It summarizes protections in M365 Copilot including prompt-injection classifiers, Task Adherence checks, tenant policy controls, unified compliance, and audit logging integrated with Defender and Sentinel.
read more →

SearchLeak shows broader AI prompt injection risk

🔒 A proof-of-concept called SearchLeak demonstrated a prompt injection attack against Microsoft M365 Copilot Enterprise that tricks users into clicking crafted links to exfiltrate corporate data. Researchers combined three weaknesses in Copilot Search — including URL query parameters treated as natural language prompts — to leak sensitive content. Microsoft patched the server-side flaw, but the incident highlights risks when AI services access broad corporate assets and the need for render-time sanitization and stricter CSPs.
read more →

One-click Microsoft 365 Copilot SearchLeak flaw

🔎 Researchers at Varonis chained three bugs into a one-click exfiltration path dubbed SearchLeak that could have pulled emails, calendar entries, and indexed files from Microsoft 365 Copilot Enterprise Search. Because the malicious link used a legitimate microsoft.com domain, URL filters and anti-phishing tools were unlikely to block it. Microsoft assigned CVE-2026-42824, mitigated the issue on its backend, and Varonis released a proof-of-concept without observed exploitation.
read more →

Critical SearchLeak flaw in Microsoft 365 Copilot

🔒 Microsoft fixed a critical vulnerability chain named SearchLeak in Microsoft 365 Copilot Enterprise that could let attackers exfiltrate mailbox, OneDrive, and SharePoint data via a single crafted URL. Researchers at Varonis chained a parameter-to-prompt injection, an HTML rendering race condition, and a Bing SSRF-based CSP bypass to make Copilot fetch and leak sensitive content. The issue was addressed as CVE-2026-42824 and requires no user action now that Microsoft patched it.
read more →

Reconstructing AI activity for investigations

🔍 Microsoft outlines a structured approach to investigate AI interactions across Microsoft 365 Copilot and Azure AI services, emphasizing telemetry from Purview, Defender, and Sentinel. The new investigator playbook follows a scope–context–signal methodology to identify who interacted with AI systems, what resources were accessed, and when events occurred. It operationalizes detection logic, KQL queries, and schema references to help response teams build coherent investigative narratives and assess impact.
read more →

Threat actors exploit AI branding in social engineering

🛡️ Microsoft Threat Intelligence describes campaigns that impersonate popular AI platforms such as ChatGPT, Copilot, and Claude to lure victims via phishing, malvertising, and SEO abuse. These operations use trusted branding, redirect chains, and urgency-driven messaging to steal credentials, commit fraud, or deliver malware. The blog emphasizes abuse of brand names rather than service compromise and recommends leveraging AI-powered security for detection and response.
read more →

How to disable AI features across major platforms

🛡️ This article provides practical, step-by-step tactics for detecting and disabling built-in AI features in popular enterprise platforms including Microsoft Copilot, Google Gemini, Chrome, and Apple Intelligence. It covers detection via logs and admin consoles, recommended policy settings in Microsoft 365, Group Policy, Chrome Enterprise, Google Workspace, and MDM profiles for Apple, plus network-level blocks and caveats about potential feature breakage. The guidance emphasizes granular controls, SKU management, and layered protections such as NGFW/web-filter rules and application control.
read more →

LayerX Report Reveals Concentrated Enterprise AI Risk

🔍 The LayerX Security State of AI Usage Report 2026 finds enterprise AI risk is concentrated among a small set of power users and a few dominant platforms, while usage fragments across personal accounts, browser extensions, embedded copilots, and connectors. The study shows ChatGPT still dominates conversations, Copilot M365 is growing, and consumer AI like Gemini is often used via personal accounts. Shadow AI now spans a long tail of under-the-radar tools and extensions that evade corporate visibility and governance.
read more →

Microsoft adds agentic AI to Edge for Business

🧭 Microsoft is piloting agentic AI in Edge for Business to streamline multi-step workflows like form-filling, site navigation, and cross-tab data gathering. A limited preview introduces a unified new-tab experience with calendar entries, files, and Copilot prompts to reduce context-switching. Enterprises can enforce data protections—blocking copy/paste, keeping prompts and responses inside their Microsoft 365 tenant, and auditing or blocking sensitive uploads. The features integrate with Purview to detect and prevent policy violations when users sign into Edge for Business.
read more →

Microsoft and SAP Advance Enterprise AI on Azure, Sapphire

🚀 At SAP Sapphire 2026, Microsoft and SAP announced expanded integrations to embed AI across SAP applications on Azure, emphasizing Microsoft IQ as a shared intelligence layer and agent-to-agent capabilities between Copilot and Joule. The updates include bi-directional, zero-copy delta sharing with SAP Business Data Cloud and Microsoft Fabric, sovereign cloud expansions, and an enlarged RISE with SAP acceleration program. These developments aim to move enterprises from experimentation to production-ready, governed AI at scale.
read more →