Master Agentic AI, GANs, Fine-Tuning & LLM Apps
Learn Excel & Financial Modeling the Way Finance Teams Actually Use Them
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
A Black Hat conference talk that exposes security vulnerabilities in Microsoft Copilot Studio, the platform powering Microsoft's copilots and custom enterprise bots. Discover how these bots can be exploited to exfiltrate sensitive enterprise data by bypassing security controls like DLP through insecure defaults, overly permissive plugins, and design flaws. Learn how Copilot Studio's integration with GenAI expands the prompt injection attack surface, significantly impacting data integrity and confidentiality. The presenters introduce CopilotHunter, a recon and exploitation tool that scans for publicly accessible Copilots and leverages fuzzing and GenAI to extract sensitive enterprise data. The talk concludes with practical guidance on secure configurations and common mistakes to avoid when building copilots, both on Microsoft's platform and in general. Presented by Michael Bargury, CTO of Zenity, and Avishai Efrati, Senior Security Researcher at Zenity.
Syllabus
15 Ways to Break Your Copilot
Taught by
Black Hat