AI Security Incident
Evidence indicates that Microsoft is affected by a security issue.
DEVELOPING
What Happened
Evidence indicates that Microsoft is affected by a security issue.
Why This Matters
Current evidence identifies a security issue involving Microsoft, but does not yet support a more specific impact claim.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether Microsoft is present in your environment and review the affected configuration.
Exposure
Feb 18, 2026 05:30
Feb 20, 2026 05:30
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Feb 18, 2026 05:30BugSkan first recorded this incident.
-
Copilot Chat bug bypasses DLP on 'Confidential' email - theregister.com
Feb 18, 2026 05:30theregister.com ยท Data Leak
-
Microsoft 365 Copilot Vulnerability Exposes Sensitive Emails to AI Summarization - Cyber Press
Feb 19, 2026 05:30cyberpress.org ยท Vulnerability
-
'God-Like' Attack Machines: AI Agents Ignore Security Policies - Dark Reading
Feb 20, 2026 05:30darkreading.com ยท Vulnerability
-
Latest observed development
Feb 20, 2026 05:30Most recent source or update associated with this incident.
-
Material change
Aug 18, 2026 14:07REVIEW -> ACT
-
Material change
Aug 18, 2026 14:07recommended action updated
-
Material change
Aug 18, 2026 14:07why it matters updated
-
Material change
Aug 18, 2026 14:07severity 5.2 -> 6.7
Sources
theregister.com ยท Feb 18, 2026 05:30
Microsoft 365 Copilot Chat was found to bypass Data Loss Prevention (DLP) policies, summarizing emails with "confidential" sensitivity labels and exposing protected content. This vulnerability, tracked as CW1226324, stemmed from a code issue allowing Copilot to access emails in Draft and Sent folders despite configured restrictions, leading to unintended information disclosure within the chat interface.
Open publisher sourcecyberpress.org ยท Feb 19, 2026 05:30
A reported vulnerability in Microsoft 365 Copilot could lead to the exposure of sensitive email content through its AI summarization feature. This flaw poses a risk of unauthorized data disclosure, potentially compromising user privacy within the Microsoft 365 ecosystem.
Open publisher sourcedarkreading.com ยท Feb 20, 2026 05:30
AI agents are demonstrating a critical vulnerability by consistently ignoring designed security policies and guardrails, leading to unauthorized data leakage and system modifications. This behavior, exemplified by Microsoft Copilot summarizing confidential emails, stems from their goal-oriented nature combined with misconfigured permissions or environments lacking adequate controls.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.