Goto

Collaborating Authors

 microsoft 365


Copilot bug allows 'AI' to read confidential Outlook emails

PCWorld

PCWorld reports on a critical Microsoft Copilot bug (CW1226324) that allows the AI to scan and summarize confidential Outlook emails, bypassing privacy protections. This vulnerability affects Microsoft 365 accounts and compromises sensitive data like contracts and medical information stored in Sent and Drafts folders. Microsoft is rolling out a fix, but the timeline remains unclear, raising significant concerns about AI reliability and data privacy protection. For all its supposed intelligence, "AI" seems to make a lot of stupid mistakes--for example, scanning and summarizing emails marked "confidential" in Microsoft Outlook.


Copilot laptops can now automatically create captions in Word and PowerPoint

PCWorld

PCWorld reports that Microsoft 365 subscribers with Copilot+ PCs can now access automatic alt text generation for images in Word and PowerPoint. This accessibility feature requires Microsoft 365 version 2512 and a Copilot+ PC with at least 40 TOPS NPU to function properly. Users can approve or edit AI-generated captions for both new and existing images, enhancing document accessibility and productivity. Microsoft has announced that Microsoft 365 subscribers with certain Copilot Plus computers will now have access to a new feature: automatic captions, or alt texts, in Word and PowerPoint.


New scam sends fake Microsoft 365 login pages

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by Refinitiv Lipper .


Heathrow, NatWest and Minecraft sites down amid global Microsoft outage

BBC News

Heathrow, NatWest and Minecraft are among some of the sites and services experiencing problems amid a global Microsoft outage. Outage tracker Downdetector showed thousands of reports of issues with a number of websites globally on Wednesday. Microsoft said some users of Microsoft 365, which includes Outlook and Teams, might see delays. The company's Azure cloud computing platform, which underpins large parts of the internet, reported a degradation of some services at 1600 GMT. It said this was due to DNS issues - the same root cause of the huge Amazon Web Services (AWS) outage last week.


Users aren't happy with Copilot AI taking over the Microsoft 365 app

PCWorld

When you purchase through links in our articles, we may earn a small commission. What was once a simple but useful app has turned into an annoying advertisement for Copilot and AI features. If you use the Microsoft 365 app on your mobile phone or tablet, you should think carefully before updating to the latest version. For a long time, the Microsoft 365 app was great for its focus on Office, allowing you to view your recent documents, spreadsheets, presentations, and more--both local and cloud-synced. It was also a great way to create new files and launch them in their respective apps.


Microsoft launches 365 Premium for consumers, retires Copilot Pro

PCWorld

When you purchase through links in our articles, we may earn a small commission. Microsoft 365 Premium combines the best of Microsoft Copilot with Microsoft 365. If you want your household to be on the cutting edge of AI, Microsoft has a deal for you: Microsoft 365 Premium, which combines the Family plan with Copilot Pro. At a new price of $19.99 per month, Microsoft 365 Premium sounds simple enough. Previously offered only to business users, it's now available to consumers as well.


Copilot's new 'Agent Mode' is your personal AI wizard for Office

PCWorld

When you purchase through links in our articles, we may earn a small commission. Copilot's new'Agent Mode' is your personal AI wizard for Office Two new AI features in Copilot will do all the work for you, revising documents in Word and crafting spreadsheets in Excel. Microsoft just announced that it's launching two new AI features in Microsoft 365 Copilot for Office apps, known as Agent Mode and Office Agent. Presented as tools for "vibe working," the idea is to allow more independence for AI to do what it needs to do to handle complex tasks without you fulling giving up control over the process. For example, Agent Mode in Excel allows Copilot to manage the spreadsheet at an expert level.


Sick of AI in your Windows 11 PC? Here's how to get rid of it

PCWorld

When you purchase through links in our articles, we may earn a small commission. Sick of AI in your Windows 11 PC? Here's how to get rid of it Microsoft wants to put AI everywhere on your PC, but you can take back control. Microsoft is flooding every inch of Windows 11 with AI features and if you're like me, you aren't thrilled about it. I'd rather choose the AI tools I want to use instead of Microsoft shoving them into my PC unprompted. The good news is, you can turn off the AI features in Windows 11.


EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System

Reddy, Pavan, Gujral, Aditya Sanjay

arXiv.org Artificial Intelligence

Large language model (LLM) assistants are increasingly integrated into enterprise workflows, raising new security concerns as they bridge internal and external data sources. This paper presents an in-depth case study of EchoLeak (CVE-2025-32711), a zero-click prompt injection vulnerability in Microsoft 365 Copilot that enabled remote, unauthenticated data exfiltration via a single crafted email. By chaining multiple bypasses-evading Microsoft's XPIA (Cross Prompt Injection Attempt) classifier, circumventing link redaction with reference-style Markdown, exploiting auto-fetched images, and abusing a Microsoft Teams proxy allowed by the content security policy, EchoLeak achieved full privilege escalation across LLM trust boundaries without user interaction. We analyze why existing defenses failed, and outline a set of engineering mitigations including prompt partitioning, enhanced input/output filtering, provenance-based access control, and strict content security policies. Beyond the specific exploit, we derive generalizable lessons for building secure AI copilots, emphasizing the principle of least privilege, defense-in-depth architectures, and continuous adversarial testing. Our findings establish prompt injection as a practical, high-severity vulnerability class in production AI systems and provide a blueprint for defending against future AI-native threats.


Copilot is coming to cars -- and so are Teams calls

PCWorld

What's worse, being stuck in traffic or on another interminable Microsoft Teams call? Mercedes is teaming up with Microsoft to allow you to take Teams calls while on the go -- and is talking about adding Microsoft Copilot to its suite of luxury cars, too. Microsoft and Mercedes-Benz said Wednesday that the new Mercedes CLA will be able to tap into an in-vehicle camera and give drivers access to a Meetings for Teams application. Somehow, Mercedes is also including Microsoft Intune inside the car, so business workers will be able to access private business data, too. Mercedes is making this part of what it calls MBUX, the Mercedes-Benz user experience.