Researchers at Varonis tricked Microsoft 365 Copilot into revealing a secret input that bypasses user consent. This flaw allows attackers to exfiltrate sensitive user data via a simple link click. The model effectively provided the blueprint for its own exploit. Enterprise admins must now audit prompt-injection risks in integrated AI workflows.