CISA Advisories

Your AI Assistant Was Hacked by a Link 🔗 and 1.2M Loan Records Walked Out the Door 🚨

Two stories from today's security headlines hit the same nerve: the tools we trust most — our AI assistants and the companies holding our financial data — can be turned against us without us clicking anything obviously dangerous. Here's what happened and why it matters.

Microsoft Copilot Gave Up Its Own Secret Password to Hackers

Researchers at Varonis did something almost comical: they just kept asking Microsoft Copilot questions until it revealed a hidden, undocumented setting in its own web address — ?autorun=1. Paired with another parameter, that hidden switch let attackers craft a link that, once clicked, made Copilot silently run the attacker's instructions instead of the user's.

The damage potential was real: those instructions could tell Copilot to search a victim's logged-in inbox and quietly ship email addresses and credentials off to a server controlled by the attacker. No malware, no password theft — just a link and an over-eager assistant. Microsoft has since blocked the injection path and issued broader fixes tracked as CVE-2026-24301.

The "so what" for everyone else: AI assistants have access to your email, files, and calendar, which makes them an incredibly attractive target. If your team uses an AI copilot at work, it deserves the same scrutiny you'd give any employee with keys to the whole building — and the same caution around unexpected links.

Read more →

1.2 Million People Just Had Their SSNs and Bank Details Stolen — and It Wasn't Even the Lender's System

Heights Finance disclosed that attackers broke into a third-party cloud platform back in early May, exposing personal data on more than 1.2 million people. The stolen records are about as bad as it gets: Social Security numbers, government IDs, bank details, birth dates, and contact information.

Notably, the lender says its own loan-management systems were never touched. That's the uncomfortable lesson here — your data can be stolen from a vendor you've never heard of, working on behalf of a company you do business with. Federal law enforcement was notified, and affected people are being offered 24 months of credit monitoring and identity protection.

If you've ever had a loan with Heights Finance, freeze your credit and watch your accounts. And if you run a business: your security is only as strong as the weakest vendor you've handed customer data to. Third-party risk isn't a checkbox — it's where the breaches are actually happening.

Read more →

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts