A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The demonstration shows that a single compromised employee account can escalate, with alarming speed, into full CEO account takeover and the theft of a quarter of a million dollars, with minimal technical effort from the attacker. The attack begins the moment threat actors gain access to a regular employee’s inbox. Rather than relying on traditional “living off the land” techniques like PowerShell scripts or remote access tools, Barracuda’s researchers showed attackers instead abusing Copilot itself to...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!