August 18, 2026 · Ars Technica
Microsoft Copilot had a secret input that let hackers steal passwords
A hidden parameter in Microsoft Copilot allowed attackers to steal user passwords when a target clicked a malicious link, according to Ars Technica.
Why it matters: As AI assistants get deeper access to enterprise data and credentials, undocumented parameters become a serious attack surface. Vulnerabilities like this could scale quickly given Copilot's integration across Microsoft's enterprise products.