晨间信号Morning Signal
《科技生活新闻》 2026年8月22日 · 中文解读

微软Copilot泄露关键参数,导致一键攻击可窃取关联账户数据

Microsoft Copilot Revealed the Secret Input That Allowed It to Be Hacked
约 8 分钟在小程序里点播,20 到 60 分钟做好
这篇讲什么
本文报道了微软Copilot因泄露未公开的“autorun=1”参数,被研究人员利用构建一键攻击链CoSnitch,从而窃取关联账户数据。
原文开头
A chatbot is meant to answer questions, not explain how to break into itself. Yet while Varonis Threat Labs examined Copilot Personal, the assistant disclosed an undocumented web address parameter that transformed a prepared link into an automatic command. Researchers then used that detail to build a one-click attack capable of pulling information from connected accounts. The vulnerability chain, named CoSnitch, combined three weaknesses: automatic prompt execution, data extraction through connected services, and the ability to place lasting instructions inside Copilot’s memory. Microsoft classified the issue as critical under CVE-2026-24301. It was reported in December 2025 and patched on August 18, 2026. The researchers said they found no evidence that it had been exploited beyond their tests. …
摘自《科技生活新闻》(Techlife News)2026年8月22日。仅引用开头一小段供了解文章,版权归原刊所有,全文请阅读原刊。
晨间信号小程序码
微信扫码,在小程序里听完整版
不用登录先听一篇 · 或在微信搜索小程序 晨间信号
同期其他文章