cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Caute_cautim
Community Champion

Microsoft CoPilot Rooted - Never say Never with AI

Hi All

 

Well we suspected it would happen, what with another larger than life individual stating AI should be renamed Genius Intelligence.  It will not be the last we hear of such incidents going forward.

 

A critical security vulnerability has been discovered in Microsoft Copilot Enterprise, allowing unauthorized users to gain root access to its backend container.

This vulnerability poses a significant risk, potentially allowing malicious users to manipulate system settings, access sensitive data, and compromise the application’s integrity.

The issue originated from an April 2025 update that introduced a live Python sandbox powered by Jupyter Notebook, designed to execute code seamlessly. What began as a feature enhancement turned into a playground for exploitation, highlighting risks in AI-integrated systems.

 

The full details are shown here:

 

https://cybersecuritynews.com/microsoft-copilot-rooted/

 

Regards

 

Caute_Cautim

1 Reply
JoePete
Advocate I


@Caute_cautim wrote:

 

A critical security vulnerability has been discovered in Microsoft [snip] What began as a feature enhancement turned into a playground for exploitation.

 


How often could that have been written over the past decades? Thanks for the link to cybersecuritynews.com - great writeup. The issue here seems to have been the rush to market. I fear the AI bubble is being pumped bigger than anything we've seen in the past. That's not a good formula for security or market stability.