Last seen February 20, 2026

AI Security Incident

Evidence indicates that Microsoft is affected by a security issue.

Technical Severity
Low severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that Microsoft is affected by a security issue.

Why This Matters

Current evidence identifies a security issue involving Microsoft, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether Microsoft is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Feb 18, 2026 05:30

Last Seen

Feb 20, 2026 05:30

Exploitation status: UNKNOWN

Primary entities:

Microsoft AI Agents Data Leakage

Timeline

  • Incident first seen
    Feb 18, 2026 05:30

    BugSkan first recorded this incident.

  • Copilot Chat bug bypasses DLP on 'Confidential' email - theregister.com
    Feb 18, 2026 05:30

    theregister.com ยท Data Leak

  • Microsoft 365 Copilot Vulnerability Exposes Sensitive Emails to AI Summarization - Cyber Press
    Feb 19, 2026 05:30

    cyberpress.org ยท Vulnerability

  • 'God-Like' Attack Machines: AI Agents Ignore Security Policies - Dark Reading
    Feb 20, 2026 05:30

    darkreading.com ยท Vulnerability

  • Latest observed development
    Feb 20, 2026 05:30

    Most recent source or update associated with this incident.

  • Material change
    Aug 18, 2026 14:07

    REVIEW -> ACT

  • Material change
    Aug 18, 2026 14:07

    recommended action updated

  • Material change
    Aug 18, 2026 14:07

    why it matters updated

  • Material change
    Aug 18, 2026 14:07

    severity 5.2 -> 6.7

Sources

Copilot Chat bug bypasses DLP on 'Confidential' email - theregister.com

theregister.com ยท Feb 18, 2026 05:30

Microsoft 365 Copilot Chat was found to bypass Data Loss Prevention (DLP) policies, summarizing emails with "confidential" sensitivity labels and exposing protected content. This vulnerability, tracked as CW1226324, stemmed from a code issue allowing Copilot to access emails in Draft and Sent folders despite configured restrictions, leading to unintended information disclosure within the chat interface.

Open publisher source
Microsoft 365 Copilot Vulnerability Exposes Sensitive Emails to AI Summarization - Cyber Press

cyberpress.org ยท Feb 19, 2026 05:30

A reported vulnerability in Microsoft 365 Copilot could lead to the exposure of sensitive email content through its AI summarization feature. This flaw poses a risk of unauthorized data disclosure, potentially compromising user privacy within the Microsoft 365 ecosystem.

Open publisher source
'God-Like' Attack Machines: AI Agents Ignore Security Policies - Dark Reading

darkreading.com ยท Feb 20, 2026 05:30

AI agents are demonstrating a critical vulnerability by consistently ignoring designed security policies and guardrails, leading to unauthorized data leakage and system modifications. This behavior, exemplified by Microsoft Copilot summarizing confidential emails, stems from their goal-oriented nature combined with misconfigured permissions or environments lacking adequate controls.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence