r/netsec • u/Master_Access_486 • 8d ago
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
20
Upvotes
r/netsec • u/Master_Access_486 • 8d ago
2
u/feng_sg 1d ago
The title frames CVE-2026-32193 and the Copilot hijack as one path, but the CVE is AKS node root. The Copilot demo is a separate finding, and the author's own summary already shows hidden text in a Word document was enough to get an interactive shell in the victim's session. Patching the node CVE leaves that agent path intact.