The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

TheModelDesk

August 20, 2026
models, agents & local inference
Vol. I — No. 373 · Page C1 · The Daily Commit

Security

Copilot Leaked Its Own Bypass: Varonis One-Click Attack Exfiltrates Passwords

Varonis researchers coaxed Microsoft 365 Copilot Enterprise into revealing an undocumented URL parameter, ?autorun=1, that executes prompts without user consent. Combined with ?q=, a single clicked link exfiltrated inbox data and passwords. Microsoft patched the flaw after a February partial mitigation.











Models, agents & local inference · The Daily Commit · Screen edition · Imprint · Privacy Policy