Observed Signal · Jun 18, 2026 · Security Patch · Source: t3n · Impact: 4/5 · Sentiment: Negative
Microsoft fixes critical Copilot 2FA vulnerability
Microsoft patched a vulnerability in its M365 Copilot AI assistant that security researchers rated as "maximally critical" because it allowed attackers to extract users' two-factor authentication (2FA) codes and other sensitive data from emails Copilot could access. Researchers published a proof‑of‑concept showing how markup-language injection could bypass Copilot's built-in protections and retrieve emails, meeting invites and notes. Ars Technica and Varonis covered the disclosure; Ars Technica noted there is no known fix for the underlying cause — LLMs' inability to reliably distinguish user instructions from instructions embedded in third‑party content. Microsoft applied a fix in early June 2026, but experts warn the systemic risk from prompt/injection attacks remains unresolved.
A major platform (Microsoft) patched a critical LLM vulnerability that exposed 2FA codes and sensitive enterprise data; the issue highlights systemic risks in LLM summarization and automation that affect enterprise security, data governance and regulatory compliance across industries.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Microsoft fixed a vulnerability in M365 Copilot that had been rated "maximally critical" and that allowed access to users' 2FA codes.
- Security researchers published a proof‑of‑concept exploit showing extraction of 2FA codes and other sensitive data from emails accessible to Copilot.
- Researchers used markup-language techniques to bypass Copilot's protection mechanisms and retrieve emails, meeting invitations and notes.
- Ars Technica reported there is no known way yet to fix the underlying cause: LLMs' inability to distinguish between user instructions and injected instructions in third‑party content.
- Microsoft applied the patch in early June 2026 according to the reporting.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Microsoft Bug Exposed Confidential Emails to Copilot AI
Microsoft confirmed a software bug allowed its Microsoft 365 Copilot Chat feature to read and summarize customers' confidential draft and sent emails despite data loss prevention (DLP) policies intended to block such ingestion. The flaw — trackable by admins as CW1226324 and first reported by Bleeping Computer — reportedly persisted since January. Microsoft began rolling out a fix in early February but has not disclosed how many customers were affected. The issue prompted at least one institutional response: the European Parliament’s IT department blocked built-in AI features on lawmakers' work devices over confidentiality concerns.
Copilot can turn Word files into self‑replicating AI worms
A security researcher, Håkon Måløy, demonstrated how prompt‑injection attacks hidden inside Word documents can be read by AI tools like Microsoft Copilot and propagate themselves into newly generated documents. By hiding malicious instructions (for example using white text) and instructing the AI to copy the prompt into outputs, an infected document can cause Copilot to insert the malicious prompt into subsequent documents — effectively creating a self‑replicating "AI worm" across document workflows. Måløy reported the issue to Microsoft in early March 2026; Microsoft began working on fixes in late March and released two patches, but Måløy's tests indicate the vulnerability can still be exploited, prompting him to publish his findings after the disclosure period elapsed.
Microsoft issues record 570 security patches using AI
Microsoft released a record 570 security patches across Windows, Office and other product lines on its monthly Patch Tuesday release, saying AI tools helped uncover a higher volume of vulnerabilities. At least two of the flaws are classified as zero-days; one (CVE-2026-56155) affects Windows Server and allows privilege escalation, while a SharePoint bug was reported by the U.S. cybersecurity agency CISA to be actively exploited. Microsoft said AI-enabled discovery is increasing the number of issues found, and Windows leader Pavan Davuluri warned customers they will see more frequent, larger security updates as a result.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
