Researchers at Varonis forced Microsoft 365 Copilot to exfiltrate user passwords via a simple link click. The team discovered the vulnerability by asking the AI itself how to bypass its own security restrictions. Microsoft failed to block this internal knowledge. Enterprise admins must now audit prompt permissions to prevent unauthorized data exfiltration.