Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Paco Hope #resist
@paco@infosec.exchange  ·  activity timestamp 5 months ago

OMG. #Microsoft#Copilot bypasses #Sharepoint #security so you don’t have to!

“CoPilot gets privileged access to SharePoint so it can index documents, but unlike the regular search feature, it doesn’t know about or respect any of the access controls you might have set up. You can get CoPilot to just dump out the contents of sensitive documents that it can see, with the bonus feature* that your access won’t show up in audit logs.”

The S in CoPilot stands for Security!

https://pivotnine.com/the-crux/archive/remembering-f00fs-of-old/

The “all the things” meme where a scribbled cartoon character has a fist raised and their mouth open like shouting. It says “Backdoor all the things!”
The “all the things” meme where a scribbled cartoon character has a fist raised and their mouth open like shouting. It says “Backdoor all the things!”
The “all the things” meme where a scribbled cartoon character has a fist raised and their mouth open like shouting. It says “Backdoor all the things!”
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.5 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login