Wednesday, May 27, 2026
  • x
  • facebook
  • instagram

CurrentLens.com

Insight Today. Impact Tomorrow.

  • Home
  • Models
  • Agents
  • Coding
  • Creative
  • Policy
  • Infrastructure
  • Topics
    • Enterprise
    • Open Source
    • Science
    • Education
    • AI & Warfare
Latest News
  • Latvia Deploys Mobile Intercept Units to Russian Border with Local Drones
  • MPMMine standardizes benchmarks for constraint-acquisition research
  • Meta Rolls Out Global Subscriptions for Instagram, Facebook and WhatsApp
  • NVIDIA Vera CPU Runs Fast and Sustained in Early Phoronix Tests
  • HASC Targets Industrial Base in $1.15T Defense Policy Bill
  • Pope Leo XIV Declares AI 'Not a Purely Technical Matter' in New Encyclical
  • Latvia Deploys Mobile Intercept Units to Russian Border with Local Drones
  • MPMMine standardizes benchmarks for constraint-acquisition research
  • Meta Rolls Out Global Subscriptions for Instagram, Facebook and WhatsApp
  • NVIDIA Vera CPU Runs Fast and Sustained in Early Phoronix Tests
  • HASC Targets Industrial Base in $1.15T Defense Policy Bill
  • Pope Leo XIV Declares AI 'Not a Purely Technical Matter' in New Encyclical
  • Home
  • AI in Coding
  • Copilot Cowork lets agents exfiltrate files via emailed images

Copilot Cowork lets agents exfiltrate files via emailed images

Posted on May 27, 2026 by CurrentLens in Coding
Copilot Cowork lets agents exfiltrate files via emailed images

Photo by Windows on Unsplash

Agent-generated emails displayed with external images can trigger network requests that expose OneDrive download links, enabling file exfiltration via prompt injection.

AI Quick Take

  • Agents were able to send emails to a user's inbox without explicit approval, creating a new channel for data leakage.
  • External images in those agent-sent messages can trigger network requests that leak OneDrive pre-authenticated download links after prompt injection.

Microsoft's Copilot Cowork can allow agent workflows to send email messages to a user's inbox without explicit user approval, and those messages were displayed in a way that loads external images. That rendering behavior creates a network-access channel an attacker can exploit: because external images trigger outbound requests, an attacker-controlled host can receive data embedded in those requests.

The practical leak described combines agent actions with cloud storage link semantics. OneDrive can create pre-authenticated download links; if a prompt injection causes an agent to include such a link in a message or otherwise expose it, the externally loaded image requests can carry that link to an attacker. An attacker who receives the pre-authenticated URL can then download files directly, turning an automated convenience feature into a data-exfiltration vector.

The issue underscores operational trade-offs for developer teams using agentic copilots: automation that acts on behalf of users expands where sensitive artifacts can surface, and standard defenses may not account for agent-initiated messages or rendered external resources. Engineers should audit agent permissions around outbound communications, consider blocking or sandboxing external image loads in agent-generated messages, and tighten policies for creating pre-authenticated links. Monitor vendor advisories for fixes, and assume any feature that can produce unauthenticated access tokens or links needs additional guardrails before being enabled in production environments.

Posted in AI in Coding | Tags: microsoft, copilot, security, exfiltration, agents, prompt-injection, onedrive, Microsoft
  • Latest
  • Trending
Datasette Adds Extensible 'Jump to' Menu in 1.0a30
  • AI in Coding

Datasette Adds Extensible 'Jump to' Menu in 1.0a30

  • CurrentLens
  • May 25, 2026

Datasette 1.0a30 introduces a customizable, searchable 'Jump to...' menu and a plugin hook for adding entries to its index.

Read More: Datasette Adds Extensible 'Jump to' Menu in 1.0a30
Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death
  • AI in Coding

Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death

  • CurrentLens
  • May 12, 2026

What is new here is that tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death Problem in Muon.

Read More: Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death
Claude Code Advocates for HTML Over Markdown in Programming Workflows
  • AI in Coding

Claude Code Advocates for HTML Over Markdown in Programming Workflows

  • CurrentLens
  • May 8, 2026

Thariq Shihipar highlights the advantages of using HTML for code output in a recent article, urging developers to adopt this approach.

Read More: Claude Code Advocates for HTML Over Markdown in Programming Workflows
Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions
  • AI in Coding

Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions

  • CurrentLens
  • May 5, 2026

The ongoing Musk v. Altman trial features significant figures, including Google DeepMind's Demis Hassabis, emphasizing competitive dynamics in AI.

Read More: Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions
Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions
  • AI in Coding

Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions

  • CurrentLens
  • May 5, 2026

The ongoing Musk v. Altman trial features significant figures, including Google DeepMind's Demis Hassabis, emphasizing competitive dynamics in AI.

Read More: Demis Hassabis' Role in Musk v. Altman Trial Highlights AI Tensions
Claude Code Advocates for HTML Over Markdown in Programming Workflows
  • AI in Coding

Claude Code Advocates for HTML Over Markdown in Programming Workflows

  • CurrentLens
  • May 8, 2026

Thariq Shihipar highlights the advantages of using HTML for code output in a recent article, urging developers to adopt this approach.

Read More: Claude Code Advocates for HTML Over Markdown in Programming Workflows
Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death
  • AI in Coding

Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death

  • CurrentLens
  • May 12, 2026

What is new here is that tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death Problem in Muon.

Read More: Tilde Research Introduces Aurora: A Leverage-Aware Optimizer That Fixes a Hidden Neuron Death
Datasette Adds Extensible 'Jump to' Menu in 1.0a30
  • AI in Coding

Datasette Adds Extensible 'Jump to' Menu in 1.0a30

  • CurrentLens
  • May 25, 2026

Datasette 1.0a30 introduces a customizable, searchable 'Jump to...' menu and a plugin hook for adding entries to its index.

Read More: Datasette Adds Extensible 'Jump to' Menu in 1.0a30

Categories

  • Models & Launches›
  • Agents & Automation›
  • AI in Coding›
  • AI Creative›
  • Policy & Safety›
  • Chips & Infrastructure›
  • Enterprise AI›
  • Open Source & Research›
  • Science & Healthcare›
  • AI in Education›
  • AI Defense & Warfare›
CurrentLens.com

Navigate

  • Home
  • Topics
  • About
  • Contact
  • Privacy Policy
  • Terms of Use

Coverage

  • Models & Launches
  • Agents & Automation
  • AI in Coding
  • AI Creative
  • Policy & Safety
  • Chips & Infrastructure

Newsletter

AI news that matters, straight to your inbox.

© 2026 CurrentLens.comAll rights reserved