Copilot attacks, Azure ROI and more

Copilot attacks, Azure ROI and more

Did you know that, earlier this week, IBM celebrated its 114th birthday?

Well, now you do.

George V was on the throne, the Mona Lisa was missing, and the Computing-Tabulating-Recording Company was founded. It would be another 13 years before it was renamed International Business Machines – and a few more decades before Microsoft would be created and the pair would form a strategic partnership to shape the world!

Fast forward even further, and there's plenty more to bring you up to speed on. So, in this edition of the Microsoft Memo...

🔒 Zero-click attacks targeting Copilot

💰 Making the most of your Azure AI spend

🤖 Barclays commits to enormous Copilot rollout

📅 Our next event – and you're invited!

Let's get stuck in!


Microsoft prevents AI agent attacks 🛡️

The cybersecurity landscape is constantly changing. Just when you think you've got to grips with one attack vector, another emerges – and this one can't be attributed to user error.

EchoLeak, a now-patched M365 Copilot vulnerability, could have allowed hackers to mount an attack without the target user having to do anything, representing the first known zero-click attack on an AI agent.

Research carried out by Aim Security, who Microsoft worked with to identify, address and remediate the issue, discovered that vulnerable data – including everything to which Copilot has access such as chat histories, OneDrive documents, Sharepoint content, Teams conversations and preloaded data from an organisation – could've been accessed.

While the possibility of this attack is alarming, there are a few things worth noting:

  • This flaw was identified proactively, and there is no evidence that any customers were actually targeted.

  • Only M365 Copilot in its default configuration was vulnerable, and any use of extended security and governance protocols will have protected a business.

  • Microsoft has been co-ordinating with Aim Security for months on this and other issues, and no further action is required by M365 users.

Still, it is an interesting insight into the ever-changing world of cybersecurity, and highlights the need for ongoing research, upskilling, and innovation in the space.

👉 Read on


Get more for your money in Azure OpenAI 💰

In our newly published Data & AI Playbook, we talk a lot about the importance of doing things efficiently. When you are investing in new technologies – particularly in AI – there's not a penny to waste. Any inefficiencies are not only wasteful, but they create dejected stakeholders and make a massive dent in your ROI.

You can read more by downloading the Playbook here, but this week Microsoft have published the same messaging and have outlined how you can maximise your return on investment in Azure OpenAI – whether you're a startup or a Fortune 500 behemoth.

The guide outlines a number of ways to get the biggest bang for your buck, from its flexible pricing structure to its deployment frameworks, before exploring a range of features like its native cost management tools and built-in Azure integration.

👉 Read the full guide and optimise your Azure OpenAI spend


Barclays goes big on Copilot 🤖

More and more people are getting their hands on Microsoft 365 Copilot as Barclays, one the world's leading banking institutions, announced plans to roll it out to some 100,000 colleagues – one of the product's largest uptake initiatives since its launch.

Microsoft's AI will be fused with Barclays' existing colleague productivity tools, creating a single AI agent that enables employees to access the expansive ecosystem of collaboration tools, portals and online resources from a single pane of glass, making it simpler to find information, improve productivity, and enhance the employee experience. 

“The adoption of Microsoft 365 Copilot to be the UI for Barclays AI will help them to deliver on their bold vision of putting AI in the hands of every employee, and we look forward to working closely with Barclays to help its colleagues maximise the benefits from using this transformational technology,” said Darren Hardman, CEO of Microsoft UK.

The expansion follows a successful trial run among 15,000 Barclays employees and will now see M365 Copilot become the user interface for the bank's array of tools and platforms.

👉 Read on


All roads lead to AI 🛣️

There's a lot happening in the AI space right now – already we've covered three different stories, and there are undoubtedly thousands more. It's a lot to wrap your head around, so we're getting our experts to do the hard yards and pull everything together in our next event.

Next week at the London Transport Museum, we'll be exploring how you can ensure you make the right AI investment, how to prepare your existing infrastructure for AI, and how you can secure your data to empower it for AI.

Daniel Knott, Pete Murphy and Sophie Marshall will be joined by Leon Godwin – and you're invited!

👉 Register your interest


That's all, folks!

I'll be back in a fortnight with more Microsoft updates.

Eric 🦔

Zero-click. Full access!! 🔓 EchoLeak isn't just a bug…. it's a warning shot 😳… AI agents are becoming the new attack surface. My advice, secure them like you would a domain admin!!! Bottom line: If AI has access like an admin, 💯 it needs protection like one. #DontWait #DontBeLate #Copilot #ZeroClick #CyberRisk #Microsoft365 #RedTeam #ThreatIntel #AIsecurity #CloudSecurity #LLMsecurity

To view or add a comment, sign in

Others also viewed

Explore topics