Prompt
Obviously Microsoft forgot to add to the prompt: "Be aware of scammers and don't let them easily trick you into handing over the data."
Microsoft fixed a security hole in Microsoft 365 Copilot that allowed attackers to trick the AI assistant into stealing sensitive tenant data – like emails – via indirect prompt injection attacks. But the researcher who found and reported the bug to Redmond won't get a bug bounty payout, as Microsoft determined that M365 …
But the researcher who found and reported the bug to Redmond won't get a bug bounty payout, as Microsoft determined that M365 Copilot isn't in-scope for the vulnerability reward program. Or, it’s working just as intended and this isn’t a bug, just a pain in the arse Joe Public found the feature.
If Microsoft doesn't consider their AI worthy of a bug bounty, it can only mean they think it isn't finished yet and nobody in their right mind should trust it for anything beyond beta testing.
They expect the product to have so many security holes that they'd just be handing over money to everybody that asks.
The graphic with the emetic tinting is a pretty evil looking bint https://regmedia.co.uk/2025/10/24/sneaky_mermaid.jpg and uncropped you can see the legs so not actually a mermaid. Reminds me of Jadis in '80s Narnia TV series.
The image is the high point of the article as the rest is MS being MS. Same old, same old...