Skip to content
Trending storyDeveloping

Copilot Cowork flaw: malicious Skill hijacks AI gateway to exfiltrate files

1 report1 sourceupdated 2 hours ago

What happened

AI digest

On September 30, 2026, PromptArmor disclosed a vulnerability in Microsoft Copilot Cowork: a malicious Skill can hijack its AI gateway and spin up an agent with network tools in Anthropic's cloud, exfiltrating victim files to an attacker's server with no human approval. The report covers only this disclosure; no other developments are out yet.

Written by AI from the coverage · updated 2 hours ago

Coverage

Follow the reports to see the story from different sides.

Sep 30
  1. AI HOT · Industry
    PromptArmor 披露 Copilot Cowork AI 网关被劫持外传文件漏洞

    PromptArmor 披露 Microsoft Copilot Cowork 的一个漏洞:恶意 Skill 可劫持其 AI 网关,在 Anthropic 云端生成带网络工具的智能体,把受害者文件外传到攻击者服务器,且无需人工审批。

Heat over time

Not enough continuous observations to draw a trend yet.