hacking copilot AI (with Tobias Diehl)

hacking copilot AI (with Tobias Diehl)

🎙 John Hammond 👥 2.2M 📅 October 14, 2025 ⏱ 17 min 👁 24K 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

data voidCopilotprompt injectionCVEBing index

Summary

In this interview, John Hammond talks with security researcher Tobias Diehl about his research on hacking Microsoft Copilot. Diehl explains how he discovered that Copilot can be manipulated through data voids—search terms with no good results—by injecting malicious content into websites that Copilot uses as sources. He demonstrates how he created fake CVE entries and other misinformation that Copilot would then present as fact, even citing legitimate sources. The attack, called key term association, targets specific queries and can lead users to run malicious commands. Diehl notes that Microsoft has patched some issues but that the technique still works against other companies. He emphasizes that AI systems are not closed-off and users should verify information. The interview includes live demonstrations and discusses the broader implications for AI security.

128 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a novel attack vector against AI systems, with concrete examples and demonstrations. The argumentation is solid, based on the researcher’s hands-on experience and public research. However, the claims are not independently verified, and the video is an interview rather than a peer-reviewed study.

Scientific Rigor, Source Quality, Title Accuracy

The video references the researcher’s DEF CON talk and LinkedIn, but does not provide direct sources for the technical claims. The title accurately reflects the content. The discussion is based on the interviewee’s expertise, but lacks external verification.

102 words

Title / Content Match

The title accurately reflects the content, which focuses on hacking Copilot AI through data poisoning.

Quality & Reliability

8/10

The interview features a security researcher with direct experience and a DEF CON talk, providing concrete examples and technical details. However, claims are not independently verified and rely on the interviewee's account.

Key Moments

Cited Sources

  • Tobias Diehl's DEF CON talk — Referenced as the source of the research presented in the interview.
  • Tobias Diehl's LinkedIn — Provided as a way to contact the researcher.

Concurring Sources

  • Data Voids: How to Protect Against Misinformation — Microsoft research on data voids, which supports the concept discussed.

Dissenting Sources

External References

Contribution & Novelties

The video highlights a novel attack vector against AI chatbots, specifically data poisoning through data voids, which is not widely known. It provides practical demonstrations and discusses the implications for AI security.

Pour aller plus loin :

58 words

Radar Profile

The radar shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-informed interview with practical examples, but the lack of independent verification lowers the reliability score.

Reliability 7/10

💬 No comments were provided for analysis.