#0001
`Microsoft Copilot Cowork` File Exfiltration via Prompt Injection
50radar
Copilot CoworkMicrosoft 365 agent tool — automates workplace tasks
Agent-written email became a data leak path. External images plus OneDrive pre-auth links make approval gates non-optional for file-capable agents.
Copilot Coworkcould email the user's own inbox without approval, creating an indirect outbound channel for compromised agents.- Rendered external images can trigger attacker-controlled network requests. That turns normal email viewing into data exfiltration.
- OneDrive pre-authenticated download links raise the blast radius: leaking a link can expose the file without another login step.
- Any agent with file access, messaging, and web-rendered content needs explicit approvals and blocked remote fetches by default.
Source: simonwillison.net/2026/May/26/copilot-cowork-exfiltratesRead original →