Microsoft has fixed a vulnerability in its Copilot AI assistant that let attackers harvest sensitive user data with a single click on a legitimate Copilot URL. The researchers who demonstrated the issue were white-hat security experts from Varonis. Varonis said the multistage attack exfiltrated data including the target’s name,