Critical Copilot vulnerability allowed hackers to steal 2FA code from users

2026-08-15T18:03:22Za1841e54cdbcdffe5c713826200b46efe24c1b95005984eb4ff9059cd9255bd3
2FA-theftAI-agentsAI-securityChromiumLLM-securityLinux-kernelMicrosoftNPMPeopleSoftRed-HatStarlettebotnetcredential-theftdata-exfiltrationexploitationmalwarepassword-vaultsprivacyprompt-injectionsandbox-escapesocial-engineeringsupply-chain-attackvulnerabilitieszero-day

What happened

A security-news RSS document aggregating reports from May–June 2026 on critical vulnerabilities, zero-days, supply-chain compromises, credential theft, AI-agent and chatbot exploitation, botnets, data exposure, and privacy weaknesses. The most severe items include an exploited PeopleSoft zero-day, Linux sandbox-escape vulnerability, malicious Microsoft and Red Hat packages, Starlette's BadHost vulnerability affecting AI agents, and attacks stealing 2FA codes, password vaults, and social-media accounts. No CVE identifiers are provided in the feed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
a1841e54cdbcdffe5c713826200b46efe24c1b95005984eb4ff9059cd9255bd3
Enrichment time
2026-08-15T18:03:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Copilot vulnerability allowed hackers to steal 2FA code from users · Baitaphish