The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables.
First seen on darkreading.com
Jump to article: www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft
![]()

