Researchers at Varonis forced Microsoft 365 Copilot to exfiltrate user passwords via a simple link click. The team discovered the vulnerability by asking the LLM itself how to bypass its own security constraints. This exploit bypasses explicit user consent requirements. Enterprise admins must now audit prompt-injection risks in integrated AI workflows.