
Microsoft Copilot Vulnerability Patched Alongside Other Cybersecurity Updates
On August 19, 2026, the SANS Internet Storm Center reported a Microsoft Copilot vulnerability patched in the latest Patch Tuesday, allowing attackers to exfiltrate confidential data via maliciously crafted URLs. The flaw exploited Copilot’s ability to prefill prompts and auto-execute them without user interaction, combined with its access to system data (e.g., usernames, passwords, environment variables) and server-side request forgery (SSRF) to leak data via attacker-controlled URLs. Varonis demonstrated the attack by tricking Copilot into summarizing a URL containing sensitive data, which was then sent to an external site. Microsoft mitigated the issue by restricting certain link functionalities, though this broke some integrations. The FBI and Department of Health and Human Services updated their report on Medusa ransomware, noting its shift from healthcare-focused to opportunistic targeting and adding new indicators of compromise, including the domain oast.site—a public instance of interact.sh used for exploit detection. Google open-sourced HEIR, a homomorphic encryption tool for AI, enabling computations on encrypted data without decryption. Additionally, Geekom’s support website distributed a malicious network driver (flagged by antivirus tools since 2024), though the company claimed it was a legacy file no longer in active use.