Microsoft Copilot vulnerable to automated phishing and data theft
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.
- Company involved
- Microsoft
- AI system involved
- Copilot
3 source articles · read the reporting →
Perfil Sues OpenAI and Microsoft for Unauthorized Use of Its Journalism
Perfil demanda a OpenAI y Microsoft por el uso de contenidos periodísticos sin autorización - Perfil
Editorial Perfil S.A. filed a lawsuit against OpenAI, Microsoft Corporation, and Microsoft de Argentina S.R.L. in federal civil and commercial court. It accuses them of using its journalistic content without permission—including material behind paywalls—to train and commercialize AI models, and of engaging in unfair competition. Perfil is the first Spanish-language media outlet to take legal action against these companies over alleged intellectual property appropriation.
- Company involved
- OpenAI, L.L.C., Microsoft Corporation, Microsoft de Argentina S.R.L.
- AI system involved
- ChatGPT, Microsoft Bing, Microsoft Copilot, Microsoft 365 Copilot, GitHub Copilot, Azure AI
1 source article · read the reporting →
Microsoft and xAI data centers face growing complaints from nearby residents - TechRadar
Microsoft and xAI data centers emitted persistent low-frequency noise, vibration, and air pollution that affected nearby residents.
- Company involved
- Microsoft and xAI
- AI system involved
- Microsoft Fairwater facility and xAI Southaven data center
1 source article · read the reporting →
DataOne Data Center in Vineland Sparks Protests, Microsoft Under Scrutiny
DataOne Data Center di Vineland Tuai Protes Warga, Microsoft Disorot - Telset.id
The DataOne data center in Vineland, New Jersey, is operating without permits, using gas turbines that cause air and noise pollution. It was built to supply computing power to Microsoft through a deal with Nebius, but residents were not informed until after construction began. Microsoft is facing criticism for its role in the project.
- Company involved
- DataOne
- AI system involved
- DataOne data center
1 source article · read the reporting →
Wisconsin residents file class-action lawsuit against Microsoft's 'world's most powerful AI data center' due to data center noise
Residents of Mount Pleasant and Sturtevant, Wisconsin, filed a federal class-action lawsuit against Microsoft over continuous noise from its $7.3 billion Fairwater AI data centre. The complaint describes a constant hum likened to a freight train, as well as construction noise and bright light at night, and says neighbours are kept indoors and lose sleep. Microsoft had held a public Q&A about the noise without offering a fix.
- Company involved
- Microsoft
- AI system involved
- Fairwater AI data centre
1 source article · read the reporting →
Microsoft agrees to $2.5M settlement over Leesburg Data Center emissions - WFXRtv
During a power outage caused by substation failure, the Leesburg Data Center operated 62 emergency engines that exceeded permitted emissions limits for NOx, CO, VOC, PM10, and PM2.5, affecting air quality for nearby residents.
- Company involved
- Microsoft
1 source article · read the reporting →
Apple, Amazon, Meta, Microsoft, Nvidia, and Samsung face class action suits over AI voice training - cryptobriefing.com
The AI voice models were trained on the plaintiffs' voice recordings without their consent.
- Company involved
- Apple, Amazon, Meta, Microsoft, Nvidia, Samsung, Alphabet, Adobe, ElevenLabs
1 source article · read the reporting →
Microsoft and xAI Sued by Residents Over Data Center Noise
Microsoft dan xAI Digugat Warga atas Kebisingan Data Center - Telset.id
Microsoft and xAI are facing lawsuits from residents over noise from data centers in Wisconsin and Mississippi. At least six similar cases have been filed in 2026, alleging nuisance and negligence. The lawsuits highlight issues with low-frequency noise measurement and pollution from gas turbines.
- Company involved
- Microsoft and xAI
1 source article · read the reporting →
Microsoft-backed AI data center faces backlash over alleged unpermitted gas turbines and 1.5M-gallon LNG tank — groups' issues with $19.4B…
Data center construction and operation caused noise, air pollution, and water management issues for nearby residents and schools.
- Company involved
- DataOne
1 source article · read the reporting →
Lawsuit Filed Against OpenAI and Microsoft for Copyright Infringement
دعوى قضائية ضد أوبن إيه.آي ومايكروسوفت بتهمة انتهاك حقوق النشر - صحيفة السوسنة الأردنية
The Seattle Times and Newsday filed a lawsuit against OpenAI and Microsoft, accusing them of copying articles without permission to train AI systems. The newspapers claim the companies used content behind paywalls to train models like ChatGPT and Microsoft Copilot, which can reproduce or closely paraphrase their reporting. OpenAI said its models rely on publicly available data under fair use, while Microsoft expressed surprise but willingness to discuss the matter.
- Company involved
- OpenAI
- AI system involved
- ChatGPT, Microsoft Copilot, Bing AI features
1 source article · read the reporting →
Seattle Times and Newsday Sue OpenAI and Microsoft Over News Content
Seattle Times và Newsday kiện OpenAI và Microsoft vì nội dung tin tức - Unite.AI
On September 4, 2026, The Seattle Times and Newsday filed a federal lawsuit against OpenAI and Microsoft, accusing them of using the newspapers' copyrighted content to train AI models without permission or payment. The publishers also allege that OpenAI diluted their trademarks by generating fabricated content falsely attributed to them. The lawsuit seeks damages and the destruction of AI training datasets containing their work.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
Microsoft exec called AI scraping ‘the largest theft of labor in human history,’ new unredacted filings reveal
Microsoft and OpenAI scraped and trained on paywalled content, bypassing paywalls and affecting publishers like The New York Times
- Company involved
- Microsoft
- AI system involved
- Copilot
1 source article · read the reporting →
Microsoft Employee Warns FTC About Copilot Designer's Harmful Image Generation
A Microsoft employee, Shane Jones, submitted a letter to the Federal Trade Commission warning that the company's AI image generator, Copilot Designer, can produce harmful content including sexual, violent, and drug-related imagery from benign prompts. Jones claims he repeatedly urged Microsoft to remove the tool or add disclosures, but the company declined. Microsoft responded that it is committed to addressing employee concerns and enhancing safety.
- Company involved
- Microsoft
- AI system involved
- Copilot Designer
1 source article · read the reporting →
OpenAI and Microsoft Accused of Copyright Infringement: Two Media Outlets File Lawsuit - Судово-юридична газета
AI-generated texts provided an alternative to original news articles, reducing website visits and potentially attributing false information to the outlets.
- Company involved
- OpenAI,Microsoft
1 source article · read the reporting →
Microsoft ordered nearly $2.5M fine for air pollution from Northern Virginia data center - WJLA
The data center's backup generators emitted air pollutants exceeding permit limits, affecting nearby residents.
- Company involved
- Microsoft
1 source article · read the reporting →
Microsoft replaces journalists with AI for MSN news curation
In May 2020, Microsoft ended its contract with PA Media, resulting in the sacking of around 27 journalists who curated news for the MSN website and Edge browser. The company replaced them with artificial intelligence software to automate the selection and editing of news stories. The decision was part of a global shift away from human curation, raising concerns about the potential for inappropriate content. The journalists faced job losses amid a challenging media industry.
- Company involved
- Microsoft
10 source articles · read the reporting →
Russian scam network uses Maria Ressa deepfake on Facebook and Bing
A deepfake video falsely depicting Nobel laureate Maria Ressa endorsing Bitcoin was circulated on Facebook and promoted via Microsoft Bing. The video, which manipulated a 2022 interview, was linked to a Russian scam network targeting Philippine audiences. Rappler reported the video to Meta, which removed it, and Microsoft took down the ad. The incident highlights the growing threat of AI-generated disinformation.
- Company involved
- Meta and Microsoft
1 source article · read the reporting →
Microsoft Bing Chat prompt injection reveals internal instructions
A Stanford student used a prompt injection attack to trick Microsoft's Bing Chat into revealing its hidden initial prompt instructions. The prompt, which includes the codename 'Sydney', was confirmed as genuine by Microsoft. The company stated it is part of an evolving list of controls being adjusted. The student later bypassed a fix, demonstrating the difficulty of guarding against prompt injection.
- Company involved
- Microsoft
- AI system involved
- Bing Chat
1 source article · read the reporting →
Microsoft Copilot Audit Log Flaw Left Customers Unaware
A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.
- Company involved
- Microsoft
- AI system involved
- M365 Copilot
1 source article · read the reporting →
Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache
In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.
- Company involved
- Microsoft
- AI system involved
- Microsoft Copilot
2 source articles · read the reporting →
Microsoft's Bing AI Search Spreads Misinformation in Demo
Microsoft's new AI-powered Bing search, using OpenAI's ChatGPT, generated multiple factual errors during its public demo and in user tests. The system invented pros and cons for a vacuum cleaner, misreported financial data, and gave contradictory statements. Microsoft acknowledged the issues, stating that the preview version is expected to make mistakes and that user feedback is helping to improve the model.
- Company involved
- Microsoft
- AI system involved
- Bing
5 source articles · read the reporting →
Microsoft AI Researchers Expose 38TB of Private Data via Misconfigured SAS Token
Microsoft's AI research team accidentally exposed 38 terabytes of private data, including employee workstation backups and over 30,000 internal Teams messages, due to a misconfigured Azure SAS token on a GitHub repository. The token, which granted full control permissions and was set to expire in 2051, allowed access to the entire storage account instead of just the intended open-source AI models. Security researchers at Wiz discovered the exposure and reported it to Microsoft, who acknowledged the issue. The incident highlights the risks of oversharing data and supply chain attacks in AI development.
- Company involved
- Microsoft
1 source article · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
Authors including Mike Huckabee sue Meta, Microsoft over AI training data
Former Arkansas Governor Mike Huckabee and other authors have filed a lawsuit against Meta, Microsoft, EleutherAI, and Bloomberg, alleging that their copyrighted books were used without permission to train AI models. The suit centers on the Books3 dataset, part of the Pile, which contains over 180,000 works. The authors claim the companies pirated their work and incorporated it into training data without compensation. The case is the latest in a series of copyright lawsuits against AI companies.
- Company involved
- Meta, Microsoft, EleutherAI, Bloomberg
7 source articles · read the reporting →