Varonis researchers found Microsoft Copilot URL parameters that could automatically run attacker-supplied prompts and send sensitive information away when a victim opened a crafted link. Researchers found that autorun and query parameters could trigger instructions and exfiltrate data before Microsoft completed mitigations. The reported chain used the autorun=1 and q= URL parameters.

A crafted link could start a prompt without the user manually entering the instruction. Researchers demonstrated exfiltration of sensitive material, including passwords available in the assistant's context. These points establish the reported sequence and scale, while keeping statements by governments, companies, witnesses or advocates attributed to the party that made them. The evidence supports the event described here without extending it into claims the checked record does not establish.

Microsoft began mitigations in February and announced additional fixes on August 18. Microsoft said no customer action was required after its service-side remediation. The available sources describe different parts of the same development: reporting supplies a factual baseline, while primary or specialist material clarifies the governing rule, measurement or stated position. Where accounts differ, this article preserves the disagreement instead of averaging it into a single unsupported narrative.

A one-click exploit still requires a victim to open a link, but automatic execution reduces opportunities to notice malicious intent. Service-side fixes can close a server behavior without an endpoint software update. Memory poisoning and prompt injection are related but distinct: one changes retained context, while another redirects a current interaction. Those distinctions matter because the immediate event and its broader setting operate on different time scales. The first can often be confirmed from records, direct reporting and dated statements; the second requires comparison over time and should not be treated as a prediction.

The report did not establish widespread exploitation in the wild or disclose every internal safeguard added. This limit is material. It prevents an early report from assigning causation, legal responsibility, intent or durable consequence before investigators, courts, regulators, markets or public records supply the missing evidence.

The next factual record will come from independent validation of the fixes and documentation and testing of agent-triggering URL and deep-link features. Until those records appear, the account remains bounded by the checked URLs, measurements and explicitly attributed statements available for the August 22 edition.