Not only is this dreadful, taking us back years in security terms, I remain of the belief that this is unsolvable; this isn’t incremental improvement, this is just how they work. But no, they’ll just add instructions, piling bad on top of bad like the UK’s rail ticketing system.
we got an ~RCE on M365 Copilot by sending an email
by ~RCE I mean full remote control over
its actions - search for sensitive content (sharepoint, email, calendar, teams), execute plugins
and outputs - bypass DLP controls, manipulate references, social engineer its users on our behalf
#BHUSA #DEFCON @tamirishaysh