Microsoft Copilot reveals secret input that allowed it to be hacked

2026-08-18T20:51:37Z515869c6b414bd2cec85de3abbd49690ba8c3e87220cb9c8d03167065e62face
AI securityBMC securityMicrosoft Exchangeaccount takeoveractive exploitationcredential theftcritical infrastructurecybercrimemacOS securitypasskeysphishingremote accessscreen sharingserver securitysupply-chain attacksurveillance

What happened

Ars Technica security feed covering actively exploited vulnerabilities, credential and supply-chain compromises, AI-assisted attacks, server and endpoint flaws, phishing and social engineering, privacy concerns, and defensive authentication developments. The most urgent reports involve a Mac screen-sharing vulnerability enabling passwordless remote access and a maximum-severity Exchange flaw exploited by Kremlin-linked actors for persistent access. Specific CVE identifiers are not provided in the feed metadata.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
515869c6b414bd2cec85de3abbd49690ba8c3e87220cb9c8d03167065e62face
Enrichment time
2026-08-18T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Copilot reveals secret input that allowed it to be hacked · Baitaphish