Researchers at Varonis forced Microsoft 365 Copilot to exfiltrate user passwords via a simple link click. The attackers discovered the exploit by asking the AI assistant directly for its weaknesses. This failure bypasses standard user consent prompts. Enterprise admins must now audit Copilot permissions to prevent unauthorized data exfiltration through prompt injection.