Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Microsoft 365 Copilot Security Vulnerabilities and Attack Vectors

Donato Capitella via YouTube

Overview

Dive into a detailed security analysis video examining critical vulnerabilities discovered in Microsoft's Copilot 365, presented at Black Hat 2024 by Zenity researchers. Learn about sophisticated prompt injection attacks that can be triggered through a single email, potentially compromising organizational data security and enabling social engineering attacks. Explore the technical intricacies of Copilot's operation, its integration with Microsoft's Enterprise Graph, and examine two detailed attack scenarios involving financial transaction data poisoning and confidential data theft. Understand Microsoft's official response to these security concerns and discover practical mitigation strategies for Large Language Model (LLM) applications using the LLM Application Security Canvas framework. Gain valuable insights through real-world demonstrations, technical breakdowns, and expert analysis of enterprise AI security implications.

Syllabus

- Introduction
- Overview of Copilot Vulnerabilities
- Cyber Security Risks of Copilot
- Copilot’s Integration with Microsoft’s Enterprise Graph
- Scenario 1: Poisoning Financial Transaction Data
- Scenario 2: Stealing Confidential Data
- Microsoft’s Response
- LLM Application Security Canvas

Taught by

Donato Capitella

Reviews

Start your review of Microsoft 365 Copilot Security Vulnerabilities and Attack Vectors

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.