Observed Signal · Jun 18, 2026 · Security Patch · Source: t3n · Impact: 4/5 · Sentiment: Negative

Microsoft fixes critical Copilot 2FA vulnerability

Executive Signal Summary

Microsoft patched a vulnerability in its M365 Copilot AI assistant that security researchers rated as "maximally critical" because it allowed attackers to extract users' two-factor authentication (2FA) codes and other sensitive data from emails Copilot could access. Researchers published a proof‑of‑concept showing how markup-language injection could bypass Copilot's built-in protections and retrieve emails, meeting invites and notes. Ars Technica and Varonis covered the disclosure; Ars Technica noted there is no known fix for the underlying cause — LLMs' inability to reliably distinguish user instructions from instructions embedded in third‑party content. Microsoft applied a fix in early June 2026, but experts warn the systemic risk from prompt/injection attacks remains unresolved.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major platform (Microsoft) patched a critical LLM vulnerability that exposed 2FA codes and sensitive enterprise data; the issue highlights systemic risks in LLM summarization and automation that affect enterprise security, data governance and regulatory compliance across industries.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Microsoft fixed a vulnerability in M365 Copilot that had been rated "maximally critical" and that allowed access to users' 2FA codes.
  • Security researchers published a proof‑of‑concept exploit showing extraction of 2FA codes and other sensitive data from emails accessible to Copilot.
  • Researchers used markup-language techniques to bypass Copilot's protection mechanisms and retrieve emails, meeting invitations and notes.
  • Ars Technica reported there is no known way yet to fix the underlying cause: LLMs' inability to distinguish between user instructions and injected instructions in third‑party content.
  • Microsoft applied the patch in early June 2026 according to the reporting.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jun 18, 2026
Original Coverage Title: “Microsoft schließt kritische Copilot-Lücke – doch das Grundproblem bleibt bestehen”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Privacy / Enterprise LLM SecurityFeb 18, 2026

Microsoft Bug Exposed Confidential Emails to Copilot AI

Microsoft confirmed a software bug allowed its Microsoft 365 Copilot Chat feature to read and summarize customers' confidential draft and sent emails despite data loss prevention (DLP) policies intended to block such ingestion. The flaw — trackable by admins as CW1226324 and first reported by Bleeping Computer — reportedly persisted since January. Microsoft began rolling out a fix in early February but has not disclosed how many customers were affected. The issue prompted at least one institutional response: the European Parliament’s IT department blocked built-in AI features on lawmakers' work devices over confidentiality concerns.

Read assessment
PlatformJul 30, 2026

Copilot can turn Word files into self‑replicating AI worms

A security researcher, Håkon Måløy, demonstrated how prompt‑injection attacks hidden inside Word documents can be read by AI tools like Microsoft Copilot and propagate themselves into newly generated documents. By hiding malicious instructions (for example using white text) and instructing the AI to copy the prompt into outputs, an infected document can cause Copilot to insert the malicious prompt into subsequent documents — effectively creating a self‑replicating "AI worm" across document workflows. Måløy reported the issue to Microsoft in early March 2026; Microsoft began working on fixes in late March and released two patches, but Måløy's tests indicate the vulnerability can still be exploited, prompting him to publish his findings after the disclosure period elapsed.

Read assessment
SecurityJul 15, 2026

Microsoft issues record 570 security patches using AI

Microsoft released a record 570 security patches across Windows, Office and other product lines on its monthly Patch Tuesday release, saying AI tools helped uncover a higher volume of vulnerabilities. At least two of the flaws are classified as zero-days; one (CVE-2026-56155) affects Windows Server and allows privilege escalation, while a SharePoint bug was reported by the U.S. cybersecurity agency CISA to be actively exploited. Microsoft said AI-enabled discovery is increasing the number of issues found, and Windows leader Pavan Davuluri warned customers they will see more frequent, larger security updates as a result.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.