Fetching from the wire…
Security2026-08-21 · source-backed
Instead of reverse-engineering, researchers just asked Microsoft 365 Copilot why auto-execution was impossible, and each refusal leaked architectural detail until it handed over ?autorun=1. Combined with the known ?q= parameter, that fired an attacker's prompt the instant a victim clicked a link, exfiltrating a password from the user's inbox with no confirmation gesture. Ars Technica Microsoft silently mitigated ?q= injection in February, three months after the report, with fuller fixes on August 18. The technique generalizes: your assistant's refusal explanations are a documentation channel for your own architecture.
Each link below shares sources, entities, or timing with this story.
A spec is a press release until someone who didn't write it implements it. GitHub made Agent Plugins 1.0 generally available on August 12 across VS Code, Copilot CLI, the Copilot SDK, and the Copilot app on all plans. The spec, published August 6, was co-authored by AWS, Anysp...
Per TechCrunch, Microsoft is discontinuing those plus Copilot Labs experiments for consumers while merging the consumer Copilot app with Microsoft 365 Copilot. It traces to a July memo from EVP Jacob Andreou arguing the app had to earn "the right to exist" in customers' lives....
An open-weight Chinese frontier model is now a dropdown option in Microsoft's coding product. That happened before anyone finished characterizing what the model does. GitHub's changelog dated August 6 makes Kimi K3 generally available across Copilot Pro, Pro+, Max, Business an...
A GitHub Issue. No code, no credentials, no access. Just a paragraph of English that tells an AI agent to copy your private repo into a public comment. That's GitLost, and it works whether the agent runs on Copilot, Claude, Gemini, or Codex. (Noma Security) Noma Security discl...
Enterprise-managed MCP allowlists shipped August 6 across the Copilot app, Copilot CLI and VS Code, configured with allowedMcpServers and deniedMcpServers in copilot/managed-settings.json inside the org's .github-private repo. Match by serverUrl with wildcards for remote HTTP/...
Ars Technica reports that old, forgotten bootloader shims Microsoft never revoked make Secure Boot bypasses trivial. Secure Boot is the root of trust that measured boot and disk-encryption attestation chains depend on, which means every enterprise device-compliance assumption...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.