The Lab · 2026-03-28 00:27:02 · GitHub Issues
A critical security flaw in Microsoft's VS Code Copilot Chat extension allowed attackers to bypass its core 'sensitive file' approval mechanism, potentially leading to remote code execution. The vulnerability, present in versions 0.37.2 and earlier, centers on the `apply_patch` function. An attacker could use a prompt-...
The Lab · 2026-04-10 09:39:30 · The Verge
Microsoft is executing a quiet but significant retreat from its aggressive AI push, stripping out 'unnecessary' Copilot buttons from core Windows 11 applications. This move directly reverses a key element of its recent user interface strategy, signaling a major course correction in how the company integrates its flagsh...
The Lab · 2026-04-13 21:02:54 · Digital Today
마이크로소프트가 자사의 기업용 AI 생산성 제품군에 오픈소스 AI 에이전트 '오픈클로'와 유사한 기능을 통합하는 방안을 비공개 테스트 중이다. 이는 기존 Microsoft 365 Copilot의 기능을 확장하여, 사용자가 자연어 명령으로 애플리케이션 내 실제 작업을 자동화할 수 있는 '에이전트' 능력을 강화하려는 전략의 일환으로 보인다. 테크크런치의 보도에 따르면, 마이크로소프트의 주요 목표는 오픈클로보다 강화된 보안 통제를 갖춘 기업용 에이전트 솔루션을 엔터프라이즈 고객에게 제공하는 것이다.
이번 움직임은 마이크로소프트가 3월에 발표한 'Copilot 코워크'와 ...
The Lab · 2026-04-28 15:54:11 · GitHub Issues
A critical security vulnerability in the expertise pipeline exposes users to session-scoped prompt injection. The `UserPromptSubmit` hook (`hooks/expertise-preflight.sh`) automatically calls `${EXPERTISE_API_URL}/expertise/search` on every prompt submission and injects the API response into the `systemMessage` field, w...
The Office · 2026-05-05 21:01:37 · The Verge
Xbox is shutting down its Copilot AI initiative across both mobile and console platforms, according to new Xbox chief Asha Sharma, in a move that signals a sharp strategic pivot away from the previous AI direction. The announcement came as part of a broader reorganization of the Xbox platform team that also brought in ...
The Lab · 2026-05-09 04:01:44 · r/sysadmin
Microsoft's Secure Score system has created a structural contradiction for enterprise administrators: the company's aggressive deployment of AI-powered productivity features directly conflicts with the security benchmarks Microsoft itself mandates. System administrators report that achieving the recommended 80% Secure ...