Sunday , July 26 2026
Copilot

Microsoft admits
Copilot reads ‘confidential emails’ bypassing DLP policies

Microsoft has admitted that a coding bug accidentally allowed Copilot Chat to access and summarize confidential emails. Microsoft said that a bug in Microsoft 365 Copilot allowed the AI assistant to access private emails, raising serious privacy issues for companies using the service.

Bleeping Computer reports, the flaw bypasses data loss prevention (DLP) policies enabled by customers who wish to keep their data shielded from Microsoft’s AI. The issue reported on Jan. 21 affects the Work tab of Copilot Chat, a feature introduced to Microsoft 365 business users in September through Word, Excel, PowerPoint, Outlook, and OneNote.

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let...
Read More
SolarWinds Patches 15 Critical Serv-U Flaws

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

CVE-2026-60137, CVE-2026-63030
Patch immediately! 2 high severity WordPress flaws found

The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
CVE-2026-60137, CVE-2026-63030  Patch immediately! 2 high severity WordPress flaws found

“We identified and addressed an issue where Microsoft 365 Copilot Chat could return content from emails labelled confidential authored by a user and stored within their Draft and Sent Items in Outlook desktop,” Microsoft said in its statement to the BBC.

“While our access controls and data protection policies remained intact, this behaviour did not meet our intended Copilot experience, which is designed to exclude protected content from Copilot access,” they added.

“A configuration update has been deployed worldwide for enterprise customers.”

A fix for the issue started rolling out earlier this month, but the company hasn’t said when it will be fully resolved. They are monitoring the situation and contacting affected users for feedback. It’s unclear how many organizations are impacted, but it seems the UK’s National Health Service (NHS) is one of them.

“Microsoft says it has rolled out an update to fix the issue, and that it “did not provide anyone access to information they weren’t already authorised to see”, BBC reported.

Microsoft Copilot Studio, launched in February 2023, enables companies to create AI assistants that are trained with their own data to automate tasks in Microsoft apps.

Since its launch, Microsoft has rapidly deployed its AI assistant, Copilot, across its tools like Word, Excel, Outlook, PowerPoint, and OneNote. In September 2025, Microsoft 365 business customers gained access to Copilot Chat, allowing direct interaction with AI agents.

Tech companies promote AI assistants as vital productivity tools, but cybersecurity experts caution that quick AI adoption introduces new security risks that organizations may find hard to manage. Companies dealing with sensitive data face particularly high stakes.

Back in 2024, security researcher Michael Bargury demonstrated how Copilot Studio bots can easily exfiltrate sensitive enterprise data, circumventing existing controls. The findings were revealed at the annual Black Hat USA 2024 security conference in Las Vegas.

According to the researcher, Copilot has an array of vulnerabilities that increase users’ risk. A combination of insecure defaults, over-permissive plugins, and wishful design thinking made data leakage “probable, not just possible,” the researcher said at the time.

Using an exploitation tool he created, the researcher scanned for publicly accessible copilots and abused them to extract sensitive enterprise data.

“Attackers can remotely take over your interactions with the Copilot. They can get the Copilot to do whatever they want on your behalf, manipulate you, and misinform your decisions. They have full control of every word the Copilot writes to you,” Bargury said.

Check Also

Zimbra

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in …