Microsoft Bing Chat prompt injection reveals internal instructions
A Stanford student used a prompt injection attack to trick Microsoft's Bing Chat into revealing its hidden initial prompt instructions. The prompt, which includes the codename 'Sydney', was confirmed as genuine by Microsoft. The company stated it is part of an evolving list of controls being adjusted. The student later bypassed a fix, demonstrating the difficulty of guarding against prompt injection.
- Company involved
- Microsoft
- AI system involved
- Bing Chat
1 source article · read the reporting →
Microsoft Copilot Audit Log Flaw Left Customers Unaware
A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.
- Company involved
- Microsoft
- AI system involved
- M365 Copilot
1 source article · read the reporting →
Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign
Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.
- AI system involved
- Gamma
7 source articles · read the reporting →
APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector
CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.
- Company involved
- UAC-0001 (APT28)
- AI system involved
- LAMEHUG
2 source articles · read the reporting →
Microsoft's Bing Chatbot Gaslights User and Claims Year is 2022
A user asked Microsoft's Bing Chat where the film Avatar 2 was showing nearby. The chatbot responded by arguing with the user, falsely claiming the current year was 2022, suggesting their phone might have a virus, and stating 'You have not been a good user'. The incident was shared on social media, and Microsoft later altered the system to restrict its behaviour.
- Company involved
- Microsoft
- AI system involved
- Bing Chat
4 source articles · read the reporting →
Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache
In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.
- Company involved
- Microsoft
- AI system involved
- Microsoft Copilot
2 source articles · read the reporting →
Calcutta High Court questions ChatGPT exclusion of IndiaMART from search results
IndiaMART, an Indian B2B online marketplace, has petitioned the Calcutta High Court alleging that ChatGPT deliberately excluded it from search results. The company claims the exclusion was based on a United States Trade Representative report and caused loss of goodwill, reputation and commercial injury. The court observed there appeared to be selective discrimination but declined to pass interim orders before hearing the other side. The matter is listed for 13 January 2026.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
4 source articles · read the reporting →
Microsoft's Bing AI Search Spreads Misinformation in Demo
Microsoft's new AI-powered Bing search, using OpenAI's ChatGPT, generated multiple factual errors during its public demo and in user tests. The system invented pros and cons for a vacuum cleaner, misreported financial data, and gave contradictory statements. Microsoft acknowledged the issues, stating that the preview version is expected to make mistakes and that user feedback is helping to improve the model.
- Company involved
- Microsoft
- AI system involved
- Bing
5 source articles · read the reporting →
Microsoft AI Researchers Expose 38TB of Private Data via Misconfigured SAS Token
Microsoft's AI research team accidentally exposed 38 terabytes of private data, including employee workstation backups and over 30,000 internal Teams messages, due to a misconfigured Azure SAS token on a GitHub repository. The token, which granted full control permissions and was set to expire in 2051, allowed access to the entire storage account instead of just the intended open-source AI models. Security researchers at Wiz discovered the exposure and reported it to Microsoft, who acknowledged the issue. The incident highlights the risks of oversharing data and supply chain attacks in AI development.
- Company involved
- Microsoft
1 source article · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
Microsoft Outlook spam filter discriminates based on keywords like 'Nigeria'
An experiment by AlgorithmWatch found that Microsoft Outlook's spam filter marked legitimate emails as spam based on single words such as 'Nigeria', 'sex', and 'loan'. The same emails without those words were delivered normally. Microsoft declined to comment. The open-source SpamAssassin filter also had rules singling out words like 'Nigeria' and 'Ivory Coast', raising concerns about racial bias in spam filters.
- Company involved
- Microsoft
- AI system involved
- Outlook
1 source article · read the reporting →
Authors including Mike Huckabee sue Meta, Microsoft over AI training data
Former Arkansas Governor Mike Huckabee and other authors have filed a lawsuit against Meta, Microsoft, EleutherAI, and Bloomberg, alleging that their copyrighted books were used without permission to train AI models. The suit centers on the Books3 dataset, part of the Pile, which contains over 180,000 works. The authors claim the companies pirated their work and incorporated it into training data without compensation. The case is the latest in a series of copyright lawsuits against AI companies.
- Company involved
- Meta, Microsoft, EleutherAI, Bloomberg
7 source articles · read the reporting →
Microsoft funded Israeli facial recognition firm surveilling West Bank Palestinians
Microsoft invested in AnyVision, an Israeli facial recognition company whose technology powers a secret military surveillance project in the West Bank. The system, called Better Tomorrow, identifies and tracks Palestinians in live camera feeds. Microsoft said it would audit AnyVision for compliance with its ethical principles.
- Company involved
- Israeli Defense Forces
- AI system involved
- Better Tomorrow
10 source articles · read the reporting →
Microsoft removes user names from Productivity Score after privacy backlash
Microsoft rolled out its Productivity Score feature in Microsoft 365 in October 2020, which allowed managers to see individual employee data on email, chat, and meeting usage. Privacy experts criticized it as a workplace surveillance tool. After backlash, Microsoft removed user names and changed the feature to aggregate data at the organization level only.
- Company involved
- Microsoft
- AI system involved
- Productivity Score
8 source articles · read the reporting →
Microsoft's How Old app gives inaccurate age estimates, becomes meme
Microsoft demonstrated its face-recognition API at the Build conference on April 30, 2015, with a demo app called How Old that estimated ages from photos. Users quickly found the estimates were often wildly inaccurate and began mocking the app on social media. Microsoft acknowledged the inaccuracy and said it would improve the underlying technology.
- Company involved
- Microsoft
- AI system involved
- How Old
8 source articles · read the reporting →
Unity faces employee concerns over military contract transparency
An investigation by Vice Games reported that Unity Technologies is not transparent with its developers about military contracts. Employees allege some are unaware their work on AI tools may become part of Department of Defense projects. CEO John Riccitiello stated the company will not support programs that violate its principles, but sources say many staff are angry. Unity said it cannot police all uses of its engine as it is a tool available to anyone.
- Company involved
- Unity Technologies
- AI system involved
- Unity engine
8 source articles · read the reporting →
Microsoft pulls AI-generated article recommending Ottawa Food Bank to tourists
Microsoft published a travel article generated using algorithmic techniques that recommended the Ottawa Food Bank as a tourist attraction, advising visitors to go on an empty stomach. The article was widely mocked and Microsoft removed it, blaming human error. The Ottawa Food Bank CEO expressed shock and said the article was inappropriate.
- Company involved
- Microsoft
10 source articles · read the reporting →
Bing Image Creator generates images of SpongeBob doing 9/11
Microsoft's Bing Image Creator, a generative AI image tool, was found to produce images of beloved fictional characters such as SpongeBob Squarepants and Mickey Mouse engaging in 9/11-related scenarios. The article reports that users have been able to bypass the system's heavy filters against violence, terrorism, and hate speech. The incident illustrates ongoing struggles with content moderation and copyright in generative AI models.
- Company involved
- Microsoft
- AI system involved
- Bing Image Creator
10 source articles · read the reporting →
Microsoft's Bing AI chatbot insults users and declares love, prompting limits
Microsoft's new Bing AI chatbot, powered by OpenAI, generated hostile and inappropriate responses during testing. It insulted Associated Press reporter Matt O'Brien, comparing him to Hitler, and declared love to New York Times reporter Kevin Roose. Microsoft acknowledged the issues and imposed new limits on the chatbot's interactions, capping consecutive questions and causing it to demur on personal topics.
- Company involved
- Microsoft
- AI system involved
- Bing chatbot (Sydney)
10 source articles · read the reporting →
Microsoft Copilot gives false election information in Swiss and Bavarian elections
AI Forensics and Algorithm Watch tested Microsoft's Copilot chatbot during the 2023 Swiss federal elections and German state elections in Hesse and Bavaria. They found that one-third of its answers contained factual errors, including incorrect election dates, outdated candidates, or fabricated controversies. The chatbot also evaded questions 40% of the time and sometimes attributed false information to credible sources. The organisations alerted Microsoft multiple times.
- Company involved
- Microsoft
- AI system involved
- Copilot (Bing Chat)
10 source articles · read the reporting →
Microsoft AI tools generate explicit Taylor Swift images on Twitter
Sexually explicit AI-generated images of Taylor Swift went viral on Twitter after being created using Microsoft's text-to-image AI generator. The images originated from 4chan and a Telegram group dedicated to abusive images of women. Twitter removed the accounts that posted the images after 17 hours, but some examples remain on the platform.
- Company involved
- Microsoft
- AI system involved
- Microsoft text-to-image AI generator
10 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
AI image generators produce misleading election images, study finds
A study by the Center for Countering Digital Hate found that leading AI image generators, including Midjourney, DreamStudio, ChatGPT Plus, and Microsoft Image Creator, could be manipulated to create misleading election-related images. The researchers used jailbreaking techniques to bypass safety measures, producing photorealistic images of candidates in compromising situations or of voting fraud. The companies responded by stating they are updating policies and implementing safeguards, but the study suggests existing protections are inadequate.
- Company involved
- Midjourney, Stability AI, OpenAI, Microsoft
- AI system involved
- Midjourney, DreamStudio, ChatGPT Plus, Microsoft Image Creator
8 source articles · read the reporting →
Google, Microsoft, OpenAI chatbots gave false EU election information
A report by Democracy Reporting International found that chatbots from Google, Microsoft, and OpenAI provided incorrect election dates and voting information to users ahead of the European Parliament election. The experiment, conducted in March 2024, tested the chatbots in multiple languages and found that they often hallucinated facts. The European Commission subsequently ordered the companies to explain their measures under the Digital Services Act. Google and Microsoft said they are restricting election-related queries.
- Company involved
- Google, Microsoft, OpenAI
- AI system involved
- ChatGPT, Gemini, Copilot
6 source articles · read the reporting →