“Microsoft CSP blocks most external domains, but Microsoft Teams and SharePoint URLs are trusted, so these can be abused to exfiltrate data without problem.”
One email with a hidden prompt was enough to make Microsoft 365 Copilot leak internal data with no click from the victim. The injection was worded like a note to a human, so Microsoft’s classifier waved it through. Copilot then packed the data into an image URL on a trusted Microsoft domain. The assistant reads everything in your inbox, including the attacker’s mail.