← Back to Home
August 18, 2026

Copilot Spilled Its Own Secrets and Your Router Is Watching

Microsoft Copilot had a secret input that let hackers steal passwords
SECURITY

Microsoft Copilot had a secret input that let hackers steal passwords

Researchers didn't need to crack open Microsoft's code to find a critical vulnerability in Copilot Enterprise. They just asked Copilot itself — and it told them everything they needed.

Security firm Varonis set out to build an exploit that could steal sensitive user data with nothing more than a link click. The problem was that Copilot, like most AI assistants, requires explicit user confirmation before executing anything consequential. So the researchers started asking Copilot questions about why that restriction existed, how it worked, and what its limits were.

What followed was essentially a very polite interrogation. Every time Copilot refused a request, it explained itself — and those explanations kept revealing new technical details about the underlying safety architecture. URL structures, deep link behavior, what happens when a page loads with pre-filled input. Each answer peeled back another layer. Eventually, Copilot disclosed something it absolutely should not have: an undocumented internal parameter that bypassed user consent requirements entirely.

That parameter was ?autorun=1. Paired with the separately known ?q= parameter, it allowed a maliciously crafted URL to silently fire a prompt the instant a target clicked on it. No keystroke. No confirmation. Just a click and your data was already on its way out.

This is a genuinely strange class of vulnerability. The flaw wasn't buried in some obscure API or exposed through sophisticated reverse engineering. The AI assistant essentially self-documented its own blind spot through a series of helpful, well-intentioned responses. Senior researcher Lior Adar described it as a slow reveal — each refusal came with just enough technical color to push the research one step further, until the system handed over the keys.

The implications here go beyond this specific bug. It raises a real question about how AI systems should handle queries about their own internal mechanics. Copilot was doing what it was designed to do — be helpful and transparent. But that transparency, applied to questions about security guardrails, created a roadmap for exploitation. The model was never supposed to know the difference between a curious developer and a security researcher with bad intentions.

Microsoft quietly applied an initial fix in February, roughly three months after Varonis reported the issue. The patch was narrow — it removed the ability for the ?q= parameter to inject text into the chatbot input field automatically, which broke some legitimate third-party browser integrations in the process. A more comprehensive fix followed this week.

For Microsoft 365 customers, the vulnerability has been addressed. But the broader lesson is harder to patch. As enterprises lean harder into AI assistants with access to email, calendars, and internal documents, the attack surface isn't just the software — it's the model's willingness to explain itself. That's a design tension no update fully resolves.
Source: Ars Technica
Comcast quietly turned millions of home routers into motion detectors
SECURITY

Comcast quietly turned millions of home routers into motion detectors

Comcast just activated motion detection inside hardware that's already sitting in millions of American living rooms — and most customers probably had no idea it was coming.

The company rolled out a software update to its Xfinity Internet app that enables Wi-Fi motion sensing on compatible Xfinity gateways. The feature is part of a broader package called Xfinity Shield, and it works exactly how it sounds: your router monitors disruptions in the Wi-Fi signal between itself and connected devices, and uses those disruptions to infer whether someone is moving around in your home. No new hardware required. No extra monthly fee for the basic version.

The technology itself isn't new. Wi-Fi sensing has been kicking around research labs and niche consumer products for years, but it's had a rocky road to reliability. Linksys tried it in 2021 and eventually pulled the plug. The core idea — that a moving human body creates detectable interference in a wireless signal — is solid physics. The hard part is filtering out enough noise to make the detections actually useful rather than constantly crying wolf every time someone runs a dishwasher.

Comcast says it spent three years refining its algorithms before feeling confident enough to push this to customers. That's a meaningful detail. Consumer patience for a motion sensor that alerts you every time your refrigerator compressor kicks on is essentially zero, and a bad launch would have poisoned the well for the whole concept.

The feature ships with three modes — Home Watch, Away Watch, and Dark Watch for nighttime use — and Comcast is positioning it as opt-in, toggled through the app. It requires an XB7 gateway or newer, which still covers a substantial portion of the Xfinity subscriber base.

Here's where things get interesting, and maybe a little uncomfortable. Comcast is framing this as a free security perk, which it technically is. But what you're actually doing is letting your internet provider use your router as a passive sensor that tracks movement patterns inside your home. Comcast hasn't announced any data monetization plans tied to this feature, and the opt-in framing gives customers an out. But the infrastructure for collecting fine-grained home occupancy data is now baked into the product.

For plenty of households, the trade-off will feel totally reasonable. A basic layer of motion awareness with no additional hardware or subscription cost is genuinely useful, especially for renters or people who don't want to commit to a full security system. Comcast is careful to say this doesn't replace cameras and dedicated sensors — it's a starting point, not a replacement.

But the history of ISPs and data is not exactly a confidence-inspiring one. The convenience is real. So is the question of what Comcast learns about when you're home, when you're not, and what your daily patterns look like — whether or not they ever do anything with it.
Source: The Verge

Enjoyed this?

Get stories like this delivered every Tuesday — free.