Hi All
Well we suspected it would happen, what with another larger than life individual stating AI should be renamed Genius Intelligence. It will not be the last we hear of such incidents going forward.
A critical security vulnerability has been discovered in Microsoft Copilot Enterprise, allowing unauthorized users to gain root access to its backend container.
This vulnerability poses a significant risk, potentially allowing malicious users to manipulate system settings, access sensitive data, and compromise the application’s integrity.
The issue originated from an April 2025 update that introduced a live Python sandbox powered by Jupyter Notebook, designed to execute code seamlessly. What began as a feature enhancement turned into a playground for exploitation, highlighting risks in AI-integrated systems.
The full details are shown here:
https://cybersecuritynews.com/microsoft-copilot-rooted/
Regards
Caute_Cautim
@Caute_cautim wrote:
A critical security vulnerability has been discovered in Microsoft [snip] What began as a feature enhancement turned into a playground for exploitation.
How often could that have been written over the past decades? Thanks for the link to cybersecuritynews.com - great writeup. The issue here seems to have been the rush to market. I fear the AI bubble is being pumped bigger than anything we've seen in the past. That's not a good formula for security or market stability.