<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft CoPilot Rooted - Never say Never with AI in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Microsoft-CoPilot-Rooted-Never-say-Never-with-AI/m-p/82880#M1694</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A critical security vulnerability has been discovered in Microsoft [snip] What began as a feature enhancement turned into a playground for exploitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;How often could that have been written over the past decades? Thanks for the link to cybersecuritynews.com - great writeup. The issue here seems to have been the rush to market. I fear the AI bubble is being pumped bigger than anything we've seen in the past. That's not a good formula for security or market stability.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Aug 2025 10:58:58 GMT</pubDate>
    <dc:creator>JoePete</dc:creator>
    <dc:date>2025-08-06T10:58:58Z</dc:date>
    <item>
      <title>Microsoft CoPilot Rooted - Never say Never with AI</title>
      <link>https://community.isc2.org/t5/Threats/Microsoft-CoPilot-Rooted-Never-say-Never-with-AI/m-p/82636#M1690</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well we suspected it would happen, what with another larger than life individual stating AI should be renamed Genius Intelligence.&amp;nbsp; It will not be the last we hear of such incidents going forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A critical security vulnerability has been discovered in Microsoft Copilot Enterprise, allowing unauthorized users to gain root access to its backend container.&lt;/P&gt;&lt;P&gt;This vulnerability poses a significant risk, potentially allowing malicious users to manipulate system settings, access sensitive data, and compromise the application’s integrity.&lt;/P&gt;&lt;P&gt;The issue originated from an April 2025 update that introduced a live Python sandbox powered by Jupyter Notebook, designed to execute code seamlessly. What began as a feature enhancement turned into a playground for exploitation, highlighting risks in AI-integrated systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The full details are shown here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://cybersecuritynews.com/microsoft-copilot-rooted/" target="_blank"&gt;https://cybersecuritynews.com/microsoft-copilot-rooted/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 22:02:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Microsoft-CoPilot-Rooted-Never-say-Never-with-AI/m-p/82636#M1690</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-07-28T22:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft CoPilot Rooted - Never say Never with AI</title>
      <link>https://community.isc2.org/t5/Threats/Microsoft-CoPilot-Rooted-Never-say-Never-with-AI/m-p/82880#M1694</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A critical security vulnerability has been discovered in Microsoft [snip] What began as a feature enhancement turned into a playground for exploitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;How often could that have been written over the past decades? Thanks for the link to cybersecuritynews.com - great writeup. The issue here seems to have been the rush to market. I fear the AI bubble is being pumped bigger than anything we've seen in the past. That's not a good formula for security or market stability.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 10:58:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Microsoft-CoPilot-Rooted-Never-say-Never-with-AI/m-p/82880#M1694</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2025-08-06T10:58:58Z</dc:date>
    </item>
  </channel>
</rss>

