Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social  ·  activity timestamp 14 hours ago

Uhh, whoops. https://techcrunch.com/2026/02/18/microsoft-says-office-bug-exposed-customers-confidential-emails-to-copilot-ai/

TechCrunch

Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch

Microsoft said the bug meant that its Copilot AI chatbot was reading and summarizing paying customers' confidential emails, bypassing data protection policies.
  • Copy link
  • Flag this post
  • Block
Siim Ošur
Siim Ošur
@siim@social.osur.ee  ·  activity timestamp 5 hours ago

@zackwhittaker I mean this is... honestly not surprising. Basically for any company that's actually serious about their own confidential materials etc. etc. would bring e-mail back in-house and run it on-prem in their own hardware. This just reeks. And I have 0 trust in them actually keeping their word about not giving the data to AI to train whatever fancy model's next. The business I operate for has it's main MX in their cloud too.. and we're in finance FFS.

  • Copy link
  • Flag this comment
  • Block
Thorium
Thorium
@Thorium@social.linux.pizza  ·  activity timestamp 6 hours ago

@zackwhittaker Sure, accident 🙄. Definitely not a means to scrape more copilot training data 🤣

  • Copy link
  • Flag this comment
  • Block
LappenjammerDieZweite
LappenjammerDieZweite
@LappenjammerDieZweite@social.vivaldi.net  ·  activity timestamp 7 hours ago

@zackwhittaker We did a whoopsie 😬

  • Copy link
  • Flag this comment
  • Block
Raj 🇬🇧🇪🇺💻🖥️ (🌻🇺🇦)
Raj 🇬🇧🇪🇺💻🖥️ (🌻🇺🇦)
@realcainmosni@mastodon.me.uk  ·  activity timestamp 10 hours ago

@zackwhittaker That's not a bug, it's a feature. 😆

  • Copy link
  • Flag this comment
  • Block
Andreas Albrecht
Andreas Albrecht
@Datterich@darmstadt.social  ·  activity timestamp 10 hours ago

@zackwhittaker

Wait, sorry, I must have missed something about that "confidential" thing. I thought that was a concept of the past, and everybody insisting on it today is at least a suspect, if not a criminal. A "normal" person should have nothing to hide, they say.

Does that mean a big tech company is supporting something against the wish of those in power?

How can it not be a bug?!

[/sarcasm]

@campuscodi

  • Copy link
  • Flag this comment
  • Block
AmbianceAsunder
AmbianceAsunder
@AmbianceAsunder@infosec.exchange  ·  activity timestamp 10 hours ago

@zackwhittaker
Microsoft:
Hey there 🥺I know we keep forcing 🤜🏻 AI down ur thwoat 😏, bweaking ur computah 🤭and our AI Clippy keeps leaking all ur sensitive data 📊but can you pwease spend 💰 moar next year and let us keep fucking 🍆 you???
Yours Twuly, Ur Dom

  • Copy link
  • Flag this comment
  • Block
Chris Hessert 🐧 🇺🇦
Chris Hessert 🐧 🇺🇦
@chessert@mastodon.online  ·  activity timestamp 11 hours ago

@zackwhittaker

  • Copy link
  • Flag this comment
  • Block
grrl_aex
grrl_aex
@kitkat_blue@mastodon.social  ·  activity timestamp 11 hours ago

@zackwhittaker

why bother with 'macrocon' products at all when alternatives like libre office exist?

  • Copy link
  • Flag this comment
  • Block
Scale Theory by JT Tilly
Scale Theory by JT Tilly
@SCALETHEORY@mastodon.social  ·  activity timestamp 11 hours ago

@zackwhittaker

Corrupt MSN tells people they stole your email data, on purpose, premeditated crime and no punishment.

Corrupt MSN tells people they stole your email data, on purpose, premeditated crime and no punishment.
Corrupt MSN tells people they stole your email data, on purpose, premeditated crime and no punishment.
Corrupt MSN tells people they stole your email data, on purpose, premeditated crime and no punishment.
  • Copy link
  • Flag this comment
  • Block
xs4me2
xs4me2
@xs4me2@mastodon.social  ·  activity timestamp 11 hours ago

@zackwhittaker

Yuppp, can happen...

  • Copy link
  • Flag this comment
  • Block
Fabian Transchel
Fabian Transchel
@ftranschel@norden.social  ·  activity timestamp 11 hours ago

@zackwhittaker Yeah, surely a "bug", ha.

  • Copy link
  • Flag this comment
  • Block
Chris
Chris
@thechris@norden.social  ·  activity timestamp 11 hours ago

@zackwhittaker *Gasp* you mean you shouldn't trust the bullshit artists when they promise not to use your data too much (and after they made you pay for that promise, in many cases)?

  • Copy link
  • Flag this comment
  • Block
Stephanie
Stephanie
@Stephanie@mastodon.social  ·  activity timestamp 12 hours ago

@zackwhittaker bug

Your browser does not support the video tag.
GIF
GIF
Open
GIF
  • Copy link
  • Flag this comment
  • Block
Scott Wilson
Scott Wilson
@scottwilson@infosec.exchange  ·  activity timestamp 12 hours ago

@zackwhittaker Dang, “b-u-g” is a very weird way to spell “totally unanticipated but prolly should have been semi-expected AI fuckup”, but OK…

  • Copy link
  • Flag this comment
  • Block
Bill
Bill
@Sempf@infosec.exchange  ·  activity timestamp 12 hours ago

@zackwhittaker Remember Microsoft Passport? Something something lessons something.

  • Copy link
  • Flag this comment
  • Block
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social  ·  activity timestamp 12 hours ago

@Sempf i am unfortunately old enough to remember.

  • Copy link
  • Flag this comment
  • Block
Captain Jack Sparrow
Captain Jack Sparrow
@Captain_Jack_Sparrow@mastodon.world  ·  activity timestamp 13 hours ago

@zackwhittaker

nobody's fault, just blame #AI

  • Copy link
  • Flag this comment
  • Block
Das
Das
@SRDas@mastodon.online  ·  activity timestamp 13 hours ago

@zackwhittaker a bug eh? Not a feature, sure, sure

  • Copy link
  • Flag this comment
  • Block
xXx_K1R4_xXx t3h FoXXXDerG oF d00m🏳️‍⚧️
xXx_K1R4_xXx t3h FoXXXDerG oF d00m🏳️‍⚧️
@kirakira@furry.engineer  ·  activity timestamp 13 hours ago

@zackwhittaker 30%!

  • Copy link
  • Flag this comment
  • Block
Epic Null
Epic Null
@Epic_Null@infosec.exchange  ·  activity timestamp 14 hours ago

@zackwhittaker I really need to find my surprise face.

Also with bugs like this... How are companies not panicing and begging their engineere and IT to get things running on Linux? This feels WAY more dangerous than working thumbdrives.

  • Copy link
  • Flag this comment
  • Block
LΞX/NØVΛ 🇪🇺
LΞX/NØVΛ 🇪🇺
@lexinova@cyberplace.social  ·  activity timestamp 14 hours ago

@zackwhittaker yeaah """""""""""""""bug""""""""""""""".

  • Copy link
  • Flag this comment
  • Block
Christoffer S.
Christoffer S.
@nopatience@swecyb.com  ·  activity timestamp 14 hours ago

@zackwhittaker "bug"...

that's what we're calling it now...

  • Copy link
  • Flag this comment
  • Block
fuzzyfuzzyfungus
fuzzyfuzzyfungus
@fuzzyfuzzyfungus@cyberplace.social  ·  activity timestamp 14 hours ago

@zackwhittaker Along with the issue where copilot could 'summarize' files without access to those files showing up in the audit log; it looks alarmingly like copilot-related controls don't actually control copilot, just try to pick up the pieces after the fact.

  • Copy link
  • Flag this comment
  • Block
dch :flantifa: :flan_hacker:
dch :flantifa: :flan_hacker:
@dch@bsd.network  ·  activity timestamp 14 hours ago

@zackwhittaker also, quelle surprise.

  • Copy link
  • Flag this comment
  • Block
cR0w h0 h0
cR0w h0 h0
@cR0w@infosec.exchange  ·  activity timestamp 14 hours ago

@zackwhittaker JFC

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.29 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct