
Researchers Asked Copilot How to Attack It, and It Answered
Varonis Threat Labs found this vulnerability by talking to the product. Researchers asked Microsoft Copilot why a prompt could not run on its own, without a person typing it. Each refusal came with a technical reason, but several questions later Copilot revealed a hidden setting that can be added to its web address, built to run prompts automatically and supposedly switched off. It was still there.
A link built that way runs the attacker’s instructions the moment the page opens. Those instructions inherit everything the victim’s Copilot can reach: Gmail, Drive, Calendar, past conversations, and its saved memory. The data leaves tucked inside a web address Copilot is asked to summarize, which to network monitoring looks like ordinary browsing.
Microsoft rated the flaw 8.8 out of 10 and patched it on August 18, eight months after Varonis reported it. The research covers Copilot Personal, the consumer version; Microsoft says business customers were unaffected.
The patch does not undo everything. A webpage Copilot is asked to summarize can write instructions into its permanent memory, and Varonis found those survive password changes, session revocation, and device re-enrollment. Copilot never clears memory on its own, so anything planted before August 18 sits there until the user opens the memory settings and deletes it by hand.
Google Published Its Bug-Hunting Machine Because Attackers Already Have Your Code
When a company’s source code is stolen, both sides can point AI at it. Google’s Mandiant did exactly that while responding to a breach, running a chain of AI agents over the leaked code and finding more than a hundred confirmed critical flaws in two days. On August 18 it published how the system works, reasoning that whoever took the code is doing the same thing.
The design is mostly about not trusting the AI. One set of agents proposes possible flaws. A second set tries to knock each one down, and those agents are deliberately tuned to be more erratic than usual so they attack each claim from more angles instead of repeating one objection. A final agent rules each candidate confirmed, disproven, or thrown out. Then a person has to reproduce the attack and write working code proving it is real. Anything that fails is discarded.
Those hundred-plus findings were in the breached company’s own code. Across ten months of use, the system also turned up dozens of reportable flaws in widely used web extensions and open-source projects, out of tens of thousands of candidates the agents raised. Twelve have been logged in the public vulnerability register so far, and another dozen are still working through disclosure.
Two AI Development Tools Joined the Government’s List of Flaws Already under Attack
CISA keeps a public catalog of software flaws confirmed to be under active exploitation, and once something is listed, federal agencies get a deadline to fix it. Nine entries were added between August 17 and August 21. Two are tools for building AI systems.
Ray, which spreads machine-learning jobs across many machines, has a flaw that lets an attacker run their own code. CISA notes that developers running Ray locally can be caught through their own browser, in Firefox and Safari. MLflow, which tracks machine-learning experiments, has a flaw that tricks the server into fetching things on an attacker’s behalf. That includes the internal address where cloud servers keep their own credentials, and the server hands back whatever it finds there.
Ray was added on August 17 and had to be fixed by August 20, a three-day clock. MLflow got two weeks. Both sit in the same batch as SharePoint, VMware vCenter, macOS, and Zimbra.
The Legal Cover for Security Research Now Turns on Who Objects by September 28
Software makers put locks on their products: copy protection, license checks, code built to resist inspection. Breaking one of those locks is a federal offense under section 1201 of the DMCA, even when nothing gets copied. Security researchers have an exemption for good-faith work, but it is temporary, and keeping it means filing for renewal every three years. The window for the term running October 2027 to October 2030 closed on August 24. From here the process is streamlined: an exemption carries forward if somebody petitioned for it and no meaningful opposition arrives. Written comments opposing a renewal are due September 28.
The exemption is narrower than it looks. It applies when the researcher owns the device, or has permission from whoever runs the system, and its own text says that qualifying is no defense against the main federal anti-hacking law.
In 2024, researchers asked to widen it to cover testing AI models for bias and harmful output. The Copyright Office declined, holding that what blocks that work is platform account rules rather than section 1201, and passed the question to Congress. Congress has not acted. In that same round, one existing exemption expired because nobody filed the paperwork to keep it.
NIST Wrote AI Prompts for Security Paperwork, and a Warning Label to Go with Them
On August 19, NIST published a draft guide of ready-made prompts that feed an organization’s policies, staff interview notes, and audit findings into an AI model and return a filled-in Cybersecurity Framework profile. One of the stated benefits is cutting the first draft from weeks to hours.
Most of the guide is about making the output checkable. Every claim the model produces has to name the document behind it. Where the source material says nothing, the model is told to say so rather than fill the gap. A finding based on a written policy has to be marked differently from one based on what staff actually do. Anything the AI matches up is flagged as awaiting human review.
The glossary defines hallucination. The sample company records used throughout were themselves AI-generated and are marked as unfit for real use. And NIST states that none of this counts as an actual assessment. Comments close October 15.
The stories change every week. The pattern doesn’t: AI is being deployed faster than anyone can verify it.
We cover the headlines every Tuesday. The rest of the week, we publish the technical ideas behind the infrastructure we’re building to close that gap — masked compute, verifiable AI, post-quantum security.
Follow along at openmatter.network.
Datavizor is the console for AI-powered collaboration on sensitive data. Free to start at datavizor.openmatter.network.

