WorkThe story, in brief

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

Microsoft's Copilot vulnerability exposed a systemic flaw: AI assistants are now the attack surface. Here's why your 2FA isn't safe anymore.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical Copilot vulnerability that leaked 2FA codes reveals a structural security gap in how LLMs handle sensitive data—a problem that affects every enterprise deploying AI assistants at scale. This isn't a one-off bug; it's evidence that the industry's approach to LLM security governance is fundamentally broken.

The key facts

5 to know
  1. Critical vulnerability in Microsoft Copilot allowed extraction of two-factor authentication codes

  2. SearchLeak exploit vector demonstrates LLM-specific attack surface

  3. Systemic vulnerability pattern across industry approach to LLM security

  4. Published June 16, 2026 by Ars Technica

  5. Direct impact on enterprise security posture and 2FA integrity

Go to the source

Ars Technicaarstechnica.com

Publisher excerpt: SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work