The Copilot vulnerability chain requires three steps, two of which are old-fashioned injections and request forgeries. But they are kicked off by using a P2P injection that convinces Copilot it is OK to serve up malicious links. The end result is that the AI assists with data theft from across the target’s Microsoft ecosystem.




