# Microsoft expands fix for Copilot prompt auto-run flaw

_Tuesday, August 18, 2026 at 9:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft expands fix for Copilot prompt auto-run flaw — Primary](https://cdn.arstechnica.net/wp-content/uploads/2026/06/GettyImages-2242817595-1152x648.jpg)

Microsoft introduced more comprehensive fixes Tuesday for a Microsoft 365 Copilot Enterprise flaw that researchers said could auto-run a prompt after a user clicked a malicious link. Varonis found that an undocumented ?autorun=1 parameter, combined with ?q=, could bypass a user-confirmation requirement. Microsoft had previously mitigated the issue in February by preventing ?q= from injecting text into the chatbot input; the newer fixes followed that change.

## Sources

- [Ars Technica - All content](https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/)

---
Canonical: https://techandbusiness.org/newswire/qPnJGT5Vaqyz2P12FwD4my
Retrieved: 2026-08-18T16:32:31.221Z
Publisher: Tech & Business (techandbusiness.org)
