Headlines 24.nl verzamelt actueel nieuws via de rss feeds van online kranten. Op elk moment geven wij al het laatste nieuws overzichtelijk weer.

Tevens kunt u inloggen om uw eigen nieuws pagina samen te stellen en zo alleen het nieuws te zien dat u interesseert.


 
 

Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it

22/08 07:15 - Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this year, following Reprompt, which bypassed Copilot guardrails by repeating queries, and SearchLeak, which Varonis said turned Microsoft 365 Copilot Enterprise into “a silent exfiltration tool. All three share the same exploit pattern: one click on a legitimate-looking link is enough.” A detailed blog, posted by Varonis on Tuesday, said the hole’s capabilities were significant.  CoSnitch relied on an attacker leveraging three different Copilot flaws, Varonis wrote:  Automatic prompt execution. “The ?q= URL parameter, combined with an undocumented parameter, causes any attacker-supplied prompt to execute instantly on page load: no click, no confirmation, no user action. One link is all it takes.” Data exfiltration to external servers. “An injected prompt can query the victim’s connected apps, such as Gmail, Drive, Calendar or OneDrive, encode the results into a URL and exfiltrate them via Copilot’s built-in URL-fetch capability to an attacker-controlled webhook.” Persistent memory poisoning via web summarization. “A crafted webpage, when summarized by Copilot, injects attacker instructions into the victim’s permanent memory store. The injection survives password changes, session revocation, and device re-enrollment, persisting forever.” But the potentially most intriguing element of the CoSnitch bug was how it was discovered: Copilot essentially revealed the hole itself.  Copilot revealed its own flaw “We prompted Copilot to explain why auto-execution was impossible, and each refusal came with a technical justification, which mapped the architecture,” the Varonis post said. Varonis then “reframed every refusal as a follow-up question, and each answer narrowed the attack surface further. Copilot then disclosed an undocumented URL parameter, unprompted, mid-refusal, including its historical behavior and every protection put in place to disable it. We built the URL exactly as described. With no click or confirmation from the user, the prompt was successfully executed automatically. Copilot wasn’t breached; it was played.” Microsoft confirmed both the flaw and the fix, emailing a statement that said, “our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques.” It also issued an MSRC disclosure labeling the hole “critical.”  But Microsoft’s emailed comments also included a statement that is not strictly accurate: It said, “enterprise customers using Microsoft 365 Copilot are not affected.” But analysts and others stressed that the complex nature of enterprise environments would often also house some consumer-grade Copilots from the personal accounts of workforce members, meaning that the flaw in the personal version could have absolutely impacted the enterprise version. This is further complicated by the fact that Microsoft also said that it “is in the process of moving toward a more unified Copilot experience,” referred to as Copilot Fusion; details of the planned product merger began to leak last month. That means that enterprise CISOs need to be concerned about flaws in the personal version of Copilot that may be carried over into the merged offering. The timing of Microsoft’s fix was also fragmented. Varonis reported the CoSnitch hole on December 31, and the company patched one element of the hole, its auto-execution capability, on February 1, noted Lior Adar, a Varonis senior security researcher, in an interview, but it didn’t complete the fix until Tuesday. That February patch “lowered the other vulnerabilities significantly,” Adar said. And, added his colleague, Chen Levy Ben Aroy, the Varonis Cloud Security Research Team leader, “LLMs are a whole new world of vulnerabilities.” Mark Tauschek, VP and distinguished analyst at Info-Tech Research Group, said that he found the Varonis methodology of tricking Copilot into revealing its own flaws powerful. Varonis used “a very sophisticated combination of social engineering on an LLM, a variety of jailbreaks, and a prompt injection attack that is very concerning in its capability,” he said. “The combination of hack vectors is what makes it more startling, as we’ve seen all of those methods alone before, but I think all three working for one exploit is new, at least from a disclosure perspective.” For CISOs, Tauschek said urgent action might be required.  “Much like in the old macro virus days in the late 90s and early 2000s, the only way to definitively stop it is to turn it off. Disable macros back then. Disable Copilot now,” Tauschek said. “There are many mitigation steps that can reduce risk to negligible, but that’s not zero. The point is, it’s just the beginning.” The money trail will make this fix difficult Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said there is a much more difficult issue involved in this case. He argued that the financial incentives for the major AI companies will make meaningfully fixing these kinds of holes almost impossible.   He pointed out that every guardrail that would fully close this class of attack degrades the product, because the same capabilities being exploited are the features that Microsoft is marketing as Copilot’s value. “The fix and the feature are in direct tension, which means these will not be cleanly patched so much as perpetually mitigated, and the eight-month window is what it looks like when a vendor is negotiating between its security obligation and its product roadmap on every single fix,” Mahapatra said. “This is the pattern CISOs must internalize: in agentic systems, the malicious action and the legitimate action are the same action with different intent, which collapses the entire signature-and-anomaly detection model that enterprise security has been built on for twenty years,” Mahapatra said. “CoSnitch is serious, but its defining property is that nothing was broken. Three chained flaws: an autorun URL parameter firing a prompt with no click, OAuth connector abuse reading full Gmail bodies rather than metadata, and persistent memory poisoning through web summarization, and every one is Copilot doing exactly what it was designed to do.” Mahapatra added that the third element of the CoSnitch flaw is the most troubling. “The memory-poisoning component is the one being undersold, and it is the most dangerous. A single summarized webpage writes attacker instructions into Copilot’s persistent memory, and that memory survives password changes, session revocation, and device re-enrollment,” he said. “Every standard incident response step leaves the injection intact. The attacker needs no persistent infrastructure after the initial write, because every future session runs under attacker-controlled context, recorded only in a memory settings UI almost no user has opened.” Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, also pointed to a bigger-picture issue that impacts all agentic and genAI deployments.  “The mechanisms behind the prompt injection part of the attack are based on the inability of the LLM to differentiate between data, the unsafe data stream coming from an external web page, and instructions which happen to be embedded in that data stream by the attacker controlling that external web page,” Villanustre said. “This is another example of why a different architectural approach to LLMs that separates data and instructions is needed to better guarantee the safety of their operation. This is not something that Microsoft or any other AI vendor has addressed to date.” ...


 
 

Meer over computer

22/08 10:30 Bedrijfsbezoek NSSG in Enschede

22/08 10:30 Tafelstandaard voor UNV/TPV intercom-binnenposten

22/08 10:30 Duitsland verlengt grenscontroles opnieuw met zes maanden

22/08 10:30 Criminele bende vermoedelijk achter inbraakgolf bij brandweerkazernes

22/08 10:30 Amsterdammers voelen zich steeds onveiliger in openbaar vervoer

22/08 10:30 Secusoft stroomlijnt documentbeheer binnen beveiligingsbedrijven

22/08 10:30 Sergio Römer Category Manager bij SmartSD

22/08 10:30 Schiphol laat ultimatum verlopen, acties beveiligers volgen

22/08 10:30 Retailers zetten fysieke beveiliging breder in dan diefstalpreventie

22/08 10:30 Snelle alarmopvolging Multiwacht leidt tot aanhouding na inbraak bouwterrein

22/08 10:30 Snaps slimme 'Specs'-bril arriveert in september, maar Nederland moet wachten

22/08 10:30 iPhone 18- dit weten we nu al over de nieuwe toestellen

22/08 10:30 Review Ring Floodlight Cam (2e gen) – Schijnwerpercamera met verhoogde resolutie

22/08 10:30  WhatsApp brengt oplossing uit voor bug die accounts blokkeert

22/08 10:30 Kopiëren en plakken tussen iPhone en Apple werkt aan een gedeeld klembord

22/08 10:30 Pop!_OS met Linux met een kosmische twist

22/08 10:30 Nothing-budgetmerk CMF komt in september met eigen open-ear-oortjes

22/08 10:30 Kerstmis wordt weer gewelddadig dankzij eerste Violent Night 2-trailer

22/08 10:30 Google Chrome krijgt mogelijkheid om Netflix-content in 4k af te spelen

22/08 10:30 Smartphone nat, vuil of oververhit na festival of dagje strand? Zo voorkom je extra schade

22/08 10:30 Versiegeschiedenis in de redder in nood

22/08 10:30 Dit zijn de kleuren van de lichtgevende 'rand' rondom de Google Pixel 11

22/08 10:30 TikTok laat je straks Disney-personages aan je video's toevoegen

22/08 10:30 Review TP-Link Tapo C245D – Betaalbare binnencamera met twee lenzen

22/08 10:30 De beste tv-instellingen voor zo krijg je vloeiend beeld

22/08 10:30 De bezem door je opschoongids voor Android en iOS

22/08 10:30 'AI-speaker van OpenAI heeft een donutvorm en kost tussen 300 en 400 dollar'

22/08 10:30 Wijlen acteur Sam Neill heeft rol in The Legend of Zelda-film

22/08 10:30 Meta krijgt boete van honderden miljoenen voor schade bij jongeren door social media

22/08 10:30 Eindeloos chatten in chatlimiet verdwijnt voor gratis versie

22/08 10:30 Samsung Galaxy S26 Ultra vs S25 welke moet je kiezen?

22/08 10:30 Welke slimme apparaten besparen de meeste energie?

22/08 10:30 Robert Pattinson is presentator Chris Hansen in nieuwe trailer van Primetime

22/08 10:30 OpenAI wil toekomstige hacks door aankomend AI-model voorkomen

22/08 10:30 PortableApps.com Platform 30.4: altijd je software op zak

22/08 10:30 Er komt toch geen Amerikaanse versie van Squid Game

22/08 10:30 Trevor Noah presenteert het Made By Google-event komende week

22/08 10:30 Thuisbatterij zonder wanneer heeft dat zin?

22/08 10:30 In dit reclamebord voor een nieuwe Netflix-film zit een levend persoon

22/08 10:30 Multi-gigabit- wat is dat eigenlijk?

22/08 10:30 Programma op X om geld mee te verdienen gaat op de schop

22/08 10:30 Netflix stelt vijfde The Witcher-seizoen stilletjes uit naar 2027

22/08 10:30  nieuwe films en series – Reacher en The Housemaid

22/08 10:30 De Apple Watch gaat er in de toekomst mogelijk heel anders uitzien

22/08 10:30 Met deze betaalbare hogedrukreinigers heb je weer een schoon terras of nette oprit

22/08 10:30 Monitor je servers met statistieken in één oogopslag

22/08 10:30 Spotify laat je in de toekomst mogelijk podcastadvertenties overslaan

22/08 10:30 De Fairphone 6 Plus staat op het punt onthuld te worden

22/08 10:30 Ook Nederland krijgt straks het goedkopere YouTube Premium Lite

22/08 10:30 Zonsverduistering op 12 met deze planner vind je de beste kijkplek

 

login Member login

Emailadres

Wachtwoord