At the Black Hat USA conference, cybersecurity researcher Michael Bargury demonstrated the vulnerabilities of Microsoft’s artificial intelligence assistant Copilot – potential attackers could use it for cyberattacks. His project indicates that organizations should review security policies when using AI technologies, including Copilot.

Image source: Ivana Tomášková / pixabay.com

Bargouri identified several methods by which attackers can use Microsoft Copilot to carry out cyberattacks. Copilot plugins, in particular, allow you to install backdoors that can be exploited when other users work with AI, and also serve as an aid in carrying out attacks that involve social engineering methods.

Using query injection, a hacker modifies the AI’s responses to suit his goals, allowing him to secretly search and extract data, bypassing standard file and information security measures. AI has also proven to be an effective weapon in social engineering attacks – Copilot can be used to create convincing phishing emails and prepare other methods of interacting with potential victims from whom a cybercriminal is trying to obtain sensitive information.

To demonstrate these vulnerabilities, Bargouri created LOLCopilot, a tool designed for ethical hackers that runs on any Microsoft 365 Copilot-enabled client using default configurations. Cybersecurity specialists can use it to explore scenarios for exploiting Copilot vulnerabilities to steal data and launch phishing attacks.

The developer points out that Microsoft Copilot’s existing default security settings are not effective enough to prevent these attacks. The availability of a tool to access and process large amounts of data demonstrates the risk involved in operating AI systems. The researcher recommends implementing additional security measures, including multi-factor authentication and strict data access control. Additionally, employees need to be educated about the risks associated with AI and have comprehensive incident response protocols in place.

admin

Share
Published by
admin

Recent Posts

The developer of laser-cooled chips made a lot of promises and is now looking for help from scientists

Details about the technology of the young company Maxwell Labs, which proposes to cool chips…

18 minutes ago

Asus Unveils Budget X870 MAX Gaming WiFi7 Motherboard for Ryzen 9000

Asus has introduced the X870 MAX Gaming WiFi7 motherboard. The new product is designed for…

51 minutes ago

Asus Unveils World’s First 610Hz Gaming Monitor — ROG XG248Q5G-P for $1,100

Asus has introduced two gaming monitors — ROG XG248Q5G-P and ROG XG32UCG. The first is…

51 minutes ago

Asus Unveils Budget X870 MAX Gaming WiFi7 Motherboard for Ryzen 9000

Asus has introduced the X870 MAX Gaming WiFi7 motherboard. The new product is designed for…

54 minutes ago

Asus Unveils World’s First 610Hz Gaming Monitor — ROG XG248Q5G-P for $1,100

Asus has introduced two gaming monitors — ROG XG248Q5G-P and ROG XG32UCG. The first is…

54 minutes ago

Asus Unveils ROG NUC 2025 Gaming Mini PC — Core Ultra 9 and GeForce RTX 5080 in a 3-liter Case for $3,335

Asus has officially unveiled the updated ROG NUC 2025 gaming mini-PC, which features high-performance hardware…

1 hour ago