Hackers turn Microsoft 365 Copilot into a one-click data theft tool
… Exfiltration proxy The three flaws being chained are a parameter-to-prompt injection, an HTML rendering race condition, and a content-security-policy CSP bypass enabled by Bing server-side request forgery SSRF . …