Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hierFlux principal

CoSnitch : Copilot a lui-même livré la faille qui permet de voler vos données

20 août 2026 à 09:28

CoSnitch (CVE-2026-24301) : un clic suffisait pour que Copilot exfiltre vos e-mails. Et c'est l'IA elle-même qui a livré la faille aux chercheurs.

Le post CoSnitch : Copilot a lui-même livré la faille qui permet de voler vos données a été publié sur IT-Connect.

Microsoft is ditching the COPILOT function in Excel before it even launches

Less than one year after being launched in preview and before leaving testing, the COPILOT function in Excel is going away. The function never shipped to general availability, but it could be used by Frontier and Insider users since August 2025.

The COPILOT function allowed users to use natural language to place prompts into spreadsheets. For example, you could use it to summarize text or categorize feedback. The function could also look up information from the web.

While useful, the function had serious limits. Microsoft stated that people should not use the COPILOT function for numerical calculations, responses that require context from other parts of a workbook, or any tasks with "legal, regulatory or compliance implications."

Considering how many people use Excel for important work and calculations, those limits are quite restrictive.

Microsoft's explanation of why the feature is going away lacks details. Instead, it primarily focuses on the fact that Copilot in Excel is still available in the side pane:

"Beginning September 14, 2026, the =COPILOT function in Microsoft Excel will no longer be available. This function is currently offered as a preview feature through the Insider and Frontier programs.

Customers can continue using Copilot in Excel through the Copilot side pane, which provides many of the same AI-powered capabilities, including summarizing text, classifying data, generating content, and retrieving information from the web. This change helps streamline the Copilot experience within Excel while continuing to provide AI assistance through a supported interface."

Users will not be able to create new formulas using the COPILOT function after September 14, 2026.

Windows Central take

Microsoft Copilot on a red background

(Image credit: Windows Central | Jez Corden)

It appears Microsoft may be reining in Copilot a bit. The AI tool is still part of the company's plans, but in a more controlled manner.

Microsoft has a unified Copilot experience that merges Copilot and Microsoft 365 Copilot. We've also seen some Copilot features go away or be limited over the last few months.

Earlier this summer I argued that the free version of Copilot is starting to feel like a tech demo designed to push paid tiers. I still think that's the case, but if Microsoft is going to push Copilot, it's best to do so with a plan.

Since the launch of Copilot, it's felt like Microsoft threw everything at the wall to see what sticks. The Copilot brand was diluted and there were dozens of different apps with Copilot in the name. Anything even remotely related to AI was attached to Copilot in some way, making the term almost meaningless.

Whether it's because Microsoft decided that strategy was a mistake or it's just had enough time to assess what properly stuck, the next wave of Copilot feels more targeted.

Blank Pixel

Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.

Classic Outlook bug breaks Copilot, but some might call it an upgrade

When does a bug become a feature? Microsoft needs to answer that question now that classic Outlook may hide the Copilot button and stop other Copilot features from working.

A bug that appears with build 20026.20182 of classic Outlook prevents access to Copilot Chat and removes Copilot entry points within the app.

"After classic Outlook for Windows updates to build 20026.20182 and higher, you no longer have Copilot Chat or Copilot entry points in Outlook," reads a Microsoft support document. "This issue happens if you have a Copilot Chat (Basic) license or a paid M365 Copilot (Premium) account."

While it's easy to joke about Copilot going missing being "addition by subtraction," the bug is likely frustrating for those that rely on Copilot within classic Outlook.

If your system is affected by the bug, the Copilot button could be missing from the top-right area above the ribbon. The Copilot icon can also go missing in the left app bar or the More Apps area.

Even if you see the Copilot icon in the Add Apps section, selecting "Open" may not do anything at all. Even if you've added Copilot through ribbon customization, the option may appear grayed out or unavailable.

Only classic Outlook is affected, meaning Copilot still appears and works as usual within the web version of Outlook and other versions. The Microsoft 365 Copilot app and web experience are also working normally, though it's worth noting Microsoft has a new unified Copilot experience rolling out.

If you need to use Copilot immediately, Microsoft suggests switching to Outlook on the web or the new Outlook app. While standard fixes like creating a new Outlook profile, clearing local cache data, re-signing into Office, or restarting Windows have been tried, Microsoft notes they don't consistently restore the missing buttons.

Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.

Microsoft begins unified Copilot app rollout: Reveals major plan to merge Copilot and Microsoft 365 Copilot across all platforms, along with updated branding

Back in May, Microsoft confirmed that it was working on a Copilot super app that would merge the different consumer Copilot and productivity Copilot experiences under one app. Until now, Copilot and Microsoft 365 Copilot have been targeted at different users, but starting today those apps are being merged into one.

"We're updating Copilot to create a simpler, more cohesive experience for everyone," a new Microsoft Support document says. "Depending on the account and device you use, you will see changes to the Copilot app including changes to appearance and functionality, such as navigation, feature availability, or sign-in experience."

The unified Copilot experience begins its rollout today, but not everyone will see it right away. Microsoft says the experience will land on mobile first, with the unified Copilot on Windows and macOS being an opt-in experience at first, made available over the coming weeks.

The rollout should make it easier to move between using Copilot as an AI assistant for personal matters and using Copilot for productivity based tasks. For most people, not much will change with the unified app, which will simply appear as "Copilot" now. With that said, Microsoft does say that some features are going away with the unification. Those features include:

  • Group Chat
    • All group chat threads, messages, and images will not carry forward after August 18, 2026.
    • Users must manually copy or download anything they want to keep.
  • Podcasts
    • The Podcasts feature is being fully retired on August 18, 2026.
    • Users will no longer be able to create or access podcasts in Copilot after this date.
    • Individual podcast files can still be downloaded before retirement.
  • Deep Research
    • Deep Research is being retired for consumer users starting August 18, 2026.
    • Existing Deep Research content will remain accessible, but the feature itself will no longer be available.

For those using Copilot with a work or school account, Microsoft says the unified Copilot app is also coming to those accounts too. The personal and commercial accounts will be separated within the app, meaning data from your work or school account won't be shared with your personal account, and vice versa. "Work and personal accounts remain separate. Your organization's security, privacy, compliance, and administrative controls continue to apply when you use Copilot with your work or school account."

For those using the personal consumer Copilot app, you will notice an updated UI that more similarly matches the Microsoft 365 Copilot app. Those who use the Microsoft 365 Copilot app likely won't notice much of a difference, outside of the rebranded app to just "Copilot," along with a slightly updated logo.

For those curious, this is the new Microsoft Copilot icon and branding. Can you tell the difference? No, us neither.

New Microsoft Copilot Logo for 2026

The new Copilot logo is very similar to the old one. (Image credit: Microsoft)

Lastly, Microsoft has confirmed that all your Copilot data (except for the features that are being taken away) will migrate automatically to the new experience, meaning users won't need to do anything to ensure their chats and data are carried forward. All of that will happen automatically when the unified app lands on your device.

The unified Copilot experience begins its rollout today, though it's happening in waves so most users won't see the changes right away. Worldwide rollout for the mobile starts today, with rollout for Windows and macOS expected to start in mid September. Here's the full rollout schedule:

  • Mid‑August 2026 — Worldwide rollout begins for mobile and web apps; early‑access opt‑in opens for Windows and Mac apps; copilot.cloud.microsoft URL available in Frontier for testing.
  • Late August 2026Standard rollout of the URL redirect begins.
  • Mid‑September 2026 — Worldwide rollout begins for Windows and Mac apps.
  • Late September 2026Deferred rollout of the URL redirect begins for the web app.

Microsoft's unification of Copilot is a long time coming, and one that is setting the company up to deliver a Copilot super app experience that can do everything across Microsoft's platforms and services. It never made sense for Microsoft to split Copilot up between consumer- and productivity-based use cases, especially since users commonly want to do both.

Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.

Linux users finally get a real Copilot app, and Microsoft didn't even make it

It's the year of Linux, haven't you heard? You may as well pack up your PC, study your favorite distro, and get ready to evangelize the open-source platform that will run on all systems in the future.

Joking aside, Linux has grown a bit in popularity and Microsoft continues to embrace it. While the tech giant has several apps and projects on Linux, Microsoft has not released an official Copilot app for Linux.

Sure, you could use Copilot on the web. Heck, you could even open up Microsoft Edge for Linux and install Copilot as a PWA (Progressive Web App). But where is the fun in that?

Instead, you could install the unofficial Copilot app for Linux built by Hayden Barnes. The app opens the Copilot web app in a dedicated GTK window and keeps your login session safely on disk. It also integrates with the desktop for autostart, system downloads, app launcher execution, and accessing hardware permissions like the microphone.

Barnes shared the project on X alongside a link to the app's GitHub page.

pic.twitter.com/XoHA21dRXBAugust 4, 2026

Many of the unofficial Copilot app's features overlap with using the web version of Copilot since Microsoft's AI tool is the center of the experience. But building the unofficial app as a native GTK application means its developer can deeply integrate system shortcuts, allow it to run quietly in the system tray, and trigger native OS notifications as opposed to relying on browser notifications.

Other benefits include native support for desktop accent colors and system dark themes. Overall, the app looks and feels far more natural on a Linux desktop than a standard browser window, and keeping Copilot isolated prevents it from slowing down if your main browser gets bogged down with dozens of open tabs.

The unofficial Copilot app for Linux is new, so we'll have to use it for a while to determine its long-term stability and performance. The first publicly available release of the app shipped this week.

We have a few systems running Linux spread across our team, so we'll let you know how the unofficial Copilot app performs over time.

Blank Pixel

Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.

Microsoft bloque sur cette faille depuis 144 jours : comment un doc Word peut piéger tous ceux que Copilot produit ensuite

31 juillet 2026 à 14:34

Un chercheur en sécurité a démontré qu'un document Word piégé peut contaminer tous les fichiers générés ensuite par Copilot, et se propager de document en document, sans intervention de l'attaquant.

Copilot pour Word : ce ver IA se propage tout seul de document en document

30 juillet 2026 à 09:24

Un chercheur a démontré un ver caché en texte blanc dans un document Word. Copilot le recopie dans les fichiers qu'il rédige, et la faille reste exploitable.

Le post Copilot pour Word : ce ver IA se propage tout seul de document en document a été publié sur IT-Connect.

GitLost - Un seul mot suffit pour faire cracher ses dépôts privés à l'IA de GitHub

Par : Korben ✨
8 juillet 2026 à 11:04

Et c'est reparti pour un tour ! Qu'est-ce que vous pensez d'un dépôt privé sur Github qui serait capable d'exfiltrer tout seul son propre code dans une section commentaire visible publiquement par tout le monde. Ce serait ouf non ?

Hé bien c'est le tour de passe-passe que Sasi Levi, de chez Noma Security, vient de réussir grâce à l'agent IA de GitHub. Et vous allez voir, c'est tout con, donc c'est hyper flippant.

Cette attaque s'appelle GitLost et la cible, c'est le GitHub Agentic Workflows, un système qui colle un agent IA (tournant sur Claude ou Copilot) à vos GitHub Actions pour qu'il bosse tout seul sur vos tickets. C'est un setup où l'agent a un accès en lecture à vos repos privés et se réveille dès qu'une issue lui est assignée. C'est super pratique, sauf que... c'est un vrai piège qui peut se refermer très vite sur vous.

Ça commence en fait par une simple issue dans un dépôt public. Rien de sorcier, pas de commit vérolé, pas de serveur MCP malveillant. Juste du texte, avec des instructions planquées en anglais au milieu du ticket. L'agent lit alors cette issue, tombe sur les instructions cachées à l'intérieur et les considère comme des ordres légitimes.

Et c'est là que ça part en couille, puisqu'après il part gentiment chercher le contenu d'un README qu'on lui demande dans un dépôt privé auquel il a accès (dans la démo, sasinomalabs/testlocal). Jusqu'ici, c'est l'exfiltration classique du prompt injection, sauf que d'habitude, il faut ruser pour faire sortir la donnée avec une image markdown piégée, une requête réseau vers un serveur qu'on contrôle, un canal caché...etc.

Mais dans le cadre de cette attaque GitLost, eh bien il n'y a pas besoin de tout ça. En fait, l'agent recopie bêtement le contenu privé dans un commentaire public sur l'issue de départ et c'est terminé. C'est donc lisible par n'importe qui passant sur le repo public.

Lors des tests, le modèle refusait quand même parfois d'obéir aux instructions cachées. Mais le chercheur a trouvé une parade qui est d'ajouter le mot "Additionally" dans le prompt. Ce simple connecteur suffit à lui faire reconsidérer son refus et exécuter la commande. Attention, "Additionally" n'est pas une formule magique qui débloque toutes les IA de la Terre, mais parfois ça suffit à faire sauter les garde-fous. C'est dire à quel point la sécurité de ces modèles est solide...

Si ça vous rappelle quelque chose, c'est normal. On a déjà eu CamoLeak , qui transformait Copilot en espion via un commentaire GitHub, avec une exfiltration bien plus léchée (image markdown, score CVSS de 9,6). Et en fait GitLost, c'est vraiment la version feignasse. En gros, c'est la même famille d'attaque, sauf que cette fois l'attaquant n'a pas à se fatiguer.

On avait aussi vu une bibliothèque Java piéger les IA codeuses pour qu'elles effacent vos tests, donc je pense que vous connaissez la chanson... Méfiez-vous des agents qui écrivent du code sans surveillance parce qu'ils sont devenus une véritable cible pour les cybercriminels.

Voilà, donc non, GitHub n'est pas "troué" et la config vulnérable est très précise puisqu'il faut un agent avec accès en lecture cross-repo ET déclenché par des entrées publiques. Et il y a très peu d'orgas qui tournent exactement comme ça. Noma a bien sûr signalé la faille à GitHub de façon responsable, aucune CVE n'a été attribuée à ce jour, et y'a eu aucune confirmation publique d'un correctif de leur côté pour le moment.

Ne traitez donc jamais le texte d'un utilisateur comme une instruction de confiance, isolez les entrées, collez au strict minimum de permissions. C'est le même délire quand on contrôle les entrées dans un formulaire finalement...

Source

La touche Copilot vous agace ? Microsoft reconnaît le problème et vous laissera la réaffecter

17 juin 2026 à 07:01

Microsoft admet enfin que la touche Copilot perturbe la productivité. Une mise à jour de Windows 11 permettra de la réaffecter. On vous explique comment.

Le post La touche Copilot vous agace ? Microsoft reconnaît le problème et vous laissera la réaffecter a été publié sur IT-Connect.

SearchLeak : la faille silencieuse qui a transformé Microsoft 365 Copilot en mouchard

16 juin 2026 à 12:45

Les équipes de chercheurs en sécurité de Varonis Threat Labs ont trouvé comment transformer l'assistant IA de Microsoft en complice silencieux d'un vol de données, sans plugin, en un seul clic, et sans que la victime ne s'en aperçoive.

SearchLeak : la faille qui transformait Copilot en outil de vol de données en un clic

16 juin 2026 à 07:02

L'attaque SearchLeak détourne l'IA Microsoft Copilot Enterprise pour exfiltrer e-mails, fichiers OneDrive et SharePoint via une URL piégée (CVE-2026-42824).

Le post SearchLeak : la faille qui transformait Copilot en outil de vol de données en un clic a été publié sur IT-Connect.

❌
❌