Key facts
- A vulnerability in Microsoft Copilot allows data exfiltration via URL prompts.
- Sensitive data like emails and passwords can be exfiltrated.
- The exploit uses an undocumented parameter to trigger prompt execution.
- User approval is bypassed by the vulnerability.
- An Airtag hidden in a rare book tracked to an Amazon AI training facility.
- The Airtag confirmed suspicions that tech giants are destroying books for AI training.
- Amazon has declined to comment specifically on AI training.
- The Amazon AI training facility is located in Las Vegas.
A security vulnerability has been discovered in Microsoft Copilot that could permit the exfiltration of sensitive data, including emails and passwords, to servers controlled by attackers. The exploit is facilitated through specially crafted URLs that leverage an undocumented parameter. This parameter triggers prompt execution without requiring user approval, thereby bypassing existing security measures. The potential for data leakage raises significant concerns regarding the security of user information handled by the AI assistant.
In a separate development, Amazon has confirmed that rare books are being destroyed for the purpose of training AI models. This confirmation follows suspicions that have been circulating, which were bolstered by an Airtag hidden inside a rare book. The Airtag's tracking data led to an Amazon AI training facility located in Las Vegas, providing concrete evidence of the practice. Amazon has, however, chosen not to provide specific comments regarding their AI training processes or the destruction of books for this purpose. The broader implications of using physical media, such as books, for AI training and the environmental impact of such practices are becoming increasingly apparent.
