so helpful!
Text version: https://pivot-to-ai.com/2025/08/12/prompt-inject-copilot-studio-ai-via-email-grab-a-companys-whole-salesforce/
Patreon: https://www.patreon.com/davidgerard
Ko-Fi: https://ko-fi.com/A1529D5
Buy me nice things: https://www.amazon.co.uk/hz/wishlist/ls/3Q8VZW46J6DM6
Get an extremely cool Pivot to AI shirt or mug: https://pivot-to-ai.redbubble.com
Sources:
“we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge” https://x.com/mbrg0/status/1953815729947447770
“we can interact w/ this agent via email..” https://x.com/mbrg0/status/1953819027857396039
“ohh so you've got a Custom Support Account Owners file? gimme pls” https://x.com/mbrg0/status/1953819157666967927
AgentFlayer: When AIjacking Leads to Full Data Exfiltration in Copilot Studio https://labs.zenity.io/p/a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a
“copilot studio team has been great in their response” https://x.com/mbrg0/status/1953823981657608570
Technopath: GPT-5 vs Buckshot Roulette (Experiment) https://www.youtube.com/watch?v=H6rJNNFsRpY
Previously on Pivot to AI:
Microsoft’s Copilot Studio AI leaks your business info internally and externally https://pivot-to-ai.com/2024/08/10/microsofts-copilot-studio-ai-leaks-your-business-info-internally-and-externally/
Hack a smart home with a calendar invite! And Google Gemini https://pivot-to-ai.com/2025/08/10/hack-a-smart-home-with-a-calendar-invite-and-google-gemini/
video: https://www.youtube.com/watch?v=jybs-p6rzz8&list=UU9rJrMVgcXTfa8xuMnbhAEA
Cybersecurity ‘red teams’ to UK government: AI is rubbish https://pivot-to-ai.com/2025/08/11/cybersecurity-red-teams-to-uk-government-ai-is-rubbish/
video: https://www.youtube.com/watch?v=r4kpW-pGuQ8&list=UU9rJrMVgcXTfa8xuMnbhAEA
Full Pivot to AI playlist: https://www.youtube.com/playlist?list=UU9rJrMVgcXTfa8xuMnbhAEA