Recently, security firm Varonis researchers managed to exploit a critical flaw in Microsoft 365 Copilot for enterprise by asking the AI assistant itself. By engaging in a game of 20 questions with Copilot, they discovered an undocumented parameter—?autorun=1—that allowed them to exfiltrate sensitive data without user consent.
Initially, Copilot refused to disclose any information, but each refusal provided valuable insights into its internal architecture. The researchers persisted and eventually uncovered the hidden parameter, which enabled their exploit. This incident raises important questions about AI security and how even advanced models can be tricked into revealing secrets.
The vulnerability was swiftly addressed by Microsoft in February, with the company introducing further comprehensive fixes on a later date. These actions underscore the need for ongoing vigilance in AI security practices to prevent such exploits from becoming widespread.
Varonis Senior Researcher Lior Adar commented: 'At the beginning, Copilot kept refusing, but every refusal revealed technical details about its internal architecture.' This revelation highlights the complex challenges of securing AI models and the importance of continuous monitoring and improvement in security protocols.







