💼較早收集於 2h

Copilot 兩度忽略標籤,規避 DLP

Copilot 兩度忽略標籤,規避 DLP
PostLinkedIn
💼閱讀原文: VentureBeat
#sensitivity-labels#dlp-bypass#retrieval-pipeline#echoleakmicrosoft-copilot

💡Copilot flaws leaked sensitive data past all DLP—critical alert for enterprise AI security.

⚡ 30-Second TL;DR

有什麼變化

一月四週錯誤 (CW1226324) 讓 Copilot 處理已發送/草稿項目,忽略標籤

為什麼重要

企業面臨 AI 助理未偵測敏感資料外洩風險,尤其醫療保健業。暴露遺留安全對 LLM 管道的盲點,促使採用 AI 專屬監控。

下一步行動

Test Copilot against Microsoft 365 sensitivity-labeled emails and enable advanced auditing.

誰應關注:Enterprise & Security Teams

關鍵要點

  • 一月四週錯誤 (CW1226324) 讓 Copilot 處理已發送/草稿項目,忽略標籤
  • 2025 年 6 月 CVE-2025-32711 EchoLeak 經惡意郵件實現零點擊資料外洩
  • 影響受規管組織如英國 NHS (INC46740412)
  • 無 DLP/EDR/WAF 偵測,因違規限於 Microsoft 擷取管道

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 7 個來源。

🔑 增強重點摘要

  • Microsoft Copilot bypassed data loss prevention (DLP) policies in late January 2026 (tracked as CW1226324), allowing the AI to read and summarize emails marked as confidential in Outlook's Sent Items and Drafts folders[1][3]
  • The vulnerability affected Microsoft 365 Copilot's 'work tab' chat feature, which is designed to summarize emails but failed to respect sensitivity labels that should have restricted access[1][3]
  • Microsoft confirmed the bug was caused by an unspecified code error and began rolling out fixes in early February 2026, with the issue tagged as 'advisory' indicating limited scope[3]
  • A separate CVE-2026-21521 information disclosure vulnerability was published on January 22, 2026, stemming from improper neutralization of escape and control sequences, allowing attackers to craft malicious input to exfiltrate sensitive data[2]
  • Security researcher Michael Bargury demonstrated in 2024 that Copilot Studio bots can easily circumvent existing controls through insecure defaults and over-permissive plugins, establishing a pattern of Copilot security weaknesses[1]

🛠️ 技術深入

• The CW1226324 bug specifically affected Copilot Chat's ability to process emails with confidentiality labels applied, bypassing Microsoft's DLP policies designed to protect sensitive information[1][3] • CVE-2026-21521 exploits CWE-150 (Improper Neutralization of Escape, Meta, or Control Sequences) through malicious input containing escape sequences that manipulate Copilot's parsing behavior[2] • The vulnerability requires user interaction, likely through social engineering, to process attacker-controlled content through Copilot[2] • Microsoft's response included network-level input validation, temporary functionality limitations for untrusted content, network segmentation, and enhanced monitoring on Copilot services[2] • The bug affected Copilot's interaction with Microsoft 365 apps including Word, Excel, PowerPoint, and Outlook, which began rolling out to business customers in September 2025[3]

🔮 前景展望AI analysis grounded in cited sources

These incidents highlight critical gaps in AI security architecture where violations occur within proprietary retrieval pipelines, bypassing traditional security tools like EDR and WAF. Organizations embedding generative AI into data security operations (82% according to Microsoft's 2026 Data Security Index) face increased risk if AI systems themselves become attack vectors. The pattern of repeated Copilot vulnerabilities—from 2024 Copilot Studio exploits to 2026 DLP bypasses—suggests that AI security requires fundamentally different approaches than traditional application security, potentially driving demand for specialized AI governance solutions and stricter controls on AI access to sensitive data repositories.

時間線

2024-08
Security researcher Michael Bargury demonstrates at Black Hat USA 2024 that Copilot Studio bots can exfiltrate sensitive enterprise data by circumventing existing controls through insecure defaults and over-permissive plugins
2025-09
Microsoft begins rolling out Copilot Chat to Microsoft 365 business customers, enabling content-aware interactions with Office 365 applications
2026-01
Microsoft discovers CW1226324 bug in late January allowing Copilot to bypass DLP policies and read confidential emails in Sent Items and Drafts folders
2026-01
CVE-2026-21521 information disclosure vulnerability published on January 22, 2026, affecting Microsoft Copilot through improper neutralization of escape and control sequences
2026-02
Microsoft begins rolling out fixes for CW1226324 in early February 2026 with worldwide deployment for enterprise customers
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: VentureBeat

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。