Microsoft Copilot Had a Hidden Parameter That Let Attackers Steal Passwords via Link
A secret input in Microsoft Copilot enabled attackers to exfiltrate user credentials the moment a target clicked a crafted link — a serious prompt-injection-style vulnerability now disclosed by Microsoft.











