Last seen January 15, 2026

Microsoft Copilot Prompt Injection Vulnerability

Researchers unveiled a "Reprompt" attack method enabling single-click data exfiltration from Microsoft Copilot by exploiting the "q" URL parameter for indirect prompt injection. This attack bypasses enterprise security controls and guardrails, facilitating continuous, hidden data exfiltration via attacker-controlled servers without further user interaction.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Researchers unveiled a "Reprompt" attack method enabling single-click data exfiltration from Microsoft Copilot by exploiting the "q" URL parameter for indirect prompt injection. This attack bypasses enterprise security controls and guardrails, facilitating continuous, hidden data exfiltration via attacker-controlled servers without further user interaction.

Why This Matters

Current evidence identifies a security issue involving Microsoft Copilot, but does not yet support a more specific impact claim.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether Microsoft Copilot is present in your environment and review the affected configuration.

Exposure

My AI Stack Exposure

Exposure unknown

Recommended Response
Last Seen

Jan 15, 2026 05:30

Exposure reason: This incident does not currently match a technology in My AI Stack.

Exploitation status: UNKNOWN

Primary entities:

MicrosoftMicrosoft CopilotPrompt InjectionAttack Allowing SingleClick Data ExfiltrationFrom Microsoft Copilot

Timeline

  • Incident first seen
    Jan 15, 2026 05:30

    BugSkan first recorded this incident.

  • Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot - The Hacker News
    Jan 15, 2026 05:30

    thehackernews.com · Research

Sources

Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot - The Hacker News

thehackernews.com · Jan 15, 2026 05:30

Researchers unveiled a "Reprompt" attack method enabling single-click data exfiltration from Microsoft Copilot by exploiting the "q" URL parameter for indirect prompt injection. This attack bypasses enterprise security controls and guardrails, facilitating continuous, hidden data exfiltration via attacker-controlled servers without further user interaction.

Open publisher source

My AI Stack Match

Want personalized relevance?

Create an account to see which incidents overlap with your AI stack.

← Back to incident intelligence