Varonis found a “Reprompt” attack that let a single link hijack Microsoft Copilot Personal sessions and exfiltrate data; Microsoft patched it in January 2026.
Fortunately, Microsoft has now begun rolling out a new emergency fix to address the issue, reports Engadget. It should be noted that the emergency fix also resolves an issue that prevented users from ...