Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data

New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data

Posted on January 15, 2026January 15, 2026 By CWS

Safety researchers at Varonis have found a brand new assault that allowed them to exfiltrate person information from Microsoft Copilot utilizing a single malicious hyperlink.

Dubbed Reprompt, the assault bypassed the LLMs information leak protections and allowed for persistent session exfiltration even after the Copilot was closed, Varonis says.

The assault leverages a Parameter 2 Immediate (P2P) injection, a double-request method, and a chain-request method to allow steady, undetectable information exfiltration.

The Reprompt Copilot assault begins with the exploitation of the ‘q’ parameter, which is used on AI platforms to ship a person’s question or immediate by way of a URL. All it takes is for the person to click on on the hyperlink.

“By together with a particular query or instruction within the q parameter, builders and customers can mechanically populate the enter subject when the web page masses, inflicting the AI system to execute the immediate instantly,” Varonis explains.

A risk actor, the cybersecurity agency notes, may abuse the characteristic to make Copilot execute undesirable actions. The assault resulted in one-click compromise and, as a result of it leveraged the energetic person session, it endured after the chat was closed.Commercial. Scroll to proceed studying.

To forestall delicate info leaks, Copilot usually fetches URLs provided that a legitimate motive has been offered, and evaluations and alters delicate info earlier than returning it.

Nonetheless, Varonis found that the protections solely utilized to the preliminary request, and that they could possibly be bypassed by supplying every request a number of occasions.

The researchers added directions for Copilot to carry out every process twice, which resulted within the LLM leaking person info.

Particularly, they requested it to fetch a URL containing a secret phrase twice. Copilot eliminated the delicate info on the primary attempt, however included it within the second response.

Subsequent, the researchers developed a sequence request, the place Copilot retrieved the brand new instruction immediately from their assault server.

Every request instructed it each to exfiltrate extra person info and to fetch one other instruction, in a steady alternate with the server.

This ongoing alternate, Varonis notes, would permit an attacker to exfiltrate as a lot info as doable, requesting extra information based mostly on earlier responses.

Moreover, with all instructions despatched from the server, hidden within the follow-up requests, victims couldn’t decide what information was leaked after the preliminary immediate.

“Consumer-side monitoring instruments gained’t catch these malicious prompts, as a result of the actual information leaks occur dynamically throughout back-and-forth communication — not from something apparent within the immediate the person submits,” Varonis says.

Microsoft has resolved the underlying challenge. The assault doesn’t have an effect on enterprise clients utilizing Microsoft 365 Copilot, Varonis notes.

Associated: ‘EchoLeak’ AI Assault Enabled Theft of Delicate Knowledge by way of Microsoft 365 Copilot

Associated: Rethinking Safety for Agentic AI

Associated: Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Associated: Militant Teams Are Experimenting With AI, and the Dangers Are Anticipated to Develop

Security Week News Tags:Attack, Copilot, Data, Microsoft, Reprompt, Silently, Siphons

Post navigation

Previous Post: Model Security Is the Wrong Frame – The Real Risk Is Workflow Security
Next Post: New Sicarii RaaS Operation Attacks Exposed RDP Services and Attempts to Exploit Fortinet Devices

Related Posts

Old Attack, New Speed: Researchers Optimize Page Cache Exploits Old Attack, New Speed: Researchers Optimize Page Cache Exploits Security Week News
New Interlock RAT Variant Distributed via FileFix Attacks New Interlock RAT Variant Distributed via FileFix Attacks Security Week News
Norwegian Police Say Pro-Russian Hackers Were Likely Behind Suspected Sabotage at a Dam Norwegian Police Say Pro-Russian Hackers Were Likely Behind Suspected Sabotage at a Dam Security Week News
Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency Many Attacks Aimed at EU Targeted OT, Says Cybersecurity Agency Security Week News
China’s GopherWhisper APT Exploits Legitimate Services China’s GopherWhisper APT Exploits Legitimate Services Security Week News
Android Update Patches Critical Remote Code Execution Flaw Android Update Patches Critical Remote Code Execution Flaw Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Isira Adithya: Journey from Prodigy to Ethical Hacker
  • Rokarolla Malware Targets Banking Apps with Advanced Tactics
  • Cyberattack on Novo Nordisk Exposes Medical and AI Data
  • Cybersecurity Firm Magnitude Secures $10M for AI Risk Management
  • Interlock and Rhysida: Shared Ransomware Tactics Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Isira Adithya: Journey from Prodigy to Ethical Hacker
  • Rokarolla Malware Targets Banking Apps with Advanced Tactics
  • Cyberattack on Novo Nordisk Exposes Medical and AI Data
  • Cybersecurity Firm Magnitude Secures $10M for AI Risk Management
  • Interlock and Rhysida: Shared Ransomware Tactics Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark