
Follow ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- Dubbed “Reprompt,” the attack used a URL parameter to steal user data.
- A single click was enough to trigger the entire attack chain.
- Attackers could pull sensitive Copilot data, even after the window closed.
Researchers have revealed a new attack that required only one click to execute, bypassing Microsoft Copilot security controls and enabling the theft of user data.
Also: How to remove…

![[CITYPNG.COM]White Google Play PlayStore Logo – 1500×1500](https://startupnews.fyi/wp-content/uploads/2025/08/CITYPNG.COMWhite-Google-Play-PlayStore-Logo-1500x1500-1-630x630.png)