ثغرات في Microsoft Copilot قد تؤدي إلى تسريب بيانات
كشفت Varonis Threat Labs عن ثلاث ثغرات في Microsoft Copilot Personal تسمح بتسريب البيانات بضغطة زر واحدة. تستغل هذه الثغرات، المسمى لها CoSnitch، معلمات URL غير موثقة.
لماذا يهم هذا الخبر؟
تسلط هذه الثغرات الضوء على أهمية التدقيق الأمني المستمر في أنظمة الذكاء الاصطناعي، خاصةً تلك التي تتكامل مع تطبيقات أخرى، لضمان حماية بيانات المستخدمين.
سياق الخبر
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced
فتح الخبر الأصلي