Microsoft 365 Copilot is in a lot of small offices now. It drafts email, summarizes files, and sits next to SharePoint and Teams. This week Microsoft shipped more complete fixes for a problem researchers at Varonis found by asking Copilot how its own safety rules worked.
Ars Technica reported it in August 2026. Copilot is supposed to wait for a real confirm before running a prompt. The researchers found an undocumented ?autorun=1 parameter. Paired with the usual ?q= field, a crafted link could fire a prompt the moment it opened. Microsoft blocked part of that path in February. Fuller fixes landed this week.
If a Mabank or Cedar Creek Lake office turned Copilot on for everyone with a license, check that the update landed. A Copilot link is still a link.
Call (903) 675-5431 if you want a short Copilot-and-365 checkup this week.
What to do now:
1. Confirm Copilot and the browser apps people actually use are current. Do not assume you are patched because you are on Microsoft.
2. Treat unexpected Copilot or “Open in Microsoft 365” links like unexpected attachments. If it did not come from someone you were already talking to, do not click it.
3. Review who has Copilot. If a front-desk login can see payroll or customer folders, Copilot can see them too.
This is not a reason to rip Copilot out. Treat it like email: useful, and a doorway. My I.T. Consultants is in Athens (109 S. Murchison St., Suite C) and works with Mabank-area businesses. Managed IT for businesses, not walk-in repair.
Sources:
https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/
https://www.csoonline.com/article/4210973/new-malware-turns-microsoft-cloud-into-its-control-center.html














