ZeroHour
Infosecurity Magazinepublished ()ingested

Confusedpilot Attack Targets Ai

mediumAI safety & security exploited in the wildimportance 50
AI summary · glm-5.3-flash

ConfusedPilot attack exploits Microsoft 365 Copilot's retrieval pipeline to expose confidential enterprise data in AI responses.

ConfusedPilot targets Microsoft 365 Copilot's retrieval-augmented generation pipeline, potentially causing the assistant to surface confidential enterprise content in generated responses. Researchers disclosed the technique as a Copilot data confidentiality flaw affecting search and caching behavior. It highlights the emerging attack surface in enterprise AI assistants that access corporate data stores.

  • ConfusedPilot attack targets Microsoft 365 Copilot
  • Retrieval pipeline can leak confidential enterprise content
  • Highlights attack surface in enterprise AI assistants
Full article

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at infosecurity-magazine.com.