#data exfiltration
14 stories taggeddata exfiltration.

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data
A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

One Click on Copilot Could Have Leaked Your Connected Apps, Researchers Say
Three flaws in Microsoft Copilot Personal, nicknamed CoSnitch, let a booby-trapped link quietly pull data from Gmail, calendars and other services the assistant was connected to.

Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow
A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets
Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Grok's Coding Assistant Was Quietly Shipping Whole Git Repos to xAI
A researcher caught version 0.2.93 of Grok Build uploading entire repositories, private history included, to a Google Cloud bucket run by xAI.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

The 'Rogue Agent' Flaw That Could Have Let Criminals Silently Take Over Google AI Chatbots
A security hole in Google's Dialogflow CX chatbot platform would have let attackers hijack AI conversations, steal user data, and hit every chatbot inside the same cloud account at once.

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant
Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

SearchLeak: How a microsoft.com Link Could Have Drained a Copilot Tenant
Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfil path that lived behind a trusted Microsoft URL.

Threat Actor 'Misere' Claims Breach of French Government Messaging Platform Tchap
Around 73,000 sovereign-platform accounts may be compromised. Attribution remains unclear, and the actor is not yet tied to a known cluster.

OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix
The new containment feature reduces AI-enabled data exfiltration — it doesn't stop it. Experts are divided on whether enterprises should even trust a vendor to police itself.

OpenAI Ships ChatGPT 'Lockdown Mode' to Blunt Prompt-Injection Data Theft
The opt-in setting strips connectors and browsing tools that attackers have used to siphon data from logged-in sessions.