Elektrine lite

← Feed

@cynicalsecurity@bsd.network

Post #1746164

2026-04-26 19:16 UTC

So, I was recently involved in the IR for a cloudy cloud issue… and thinking it over I realised that the attackers really haven't moved into the LLM age. Why do attackers against M365 actually _look_ for files so that they land in the logs? If they have obtained valid credentials then they can use Copilot, set it to the whatever-it-is-called-not-Web mode, and go and hunt. They could even use a "Research" agent to find which documents the user has access to which contain juicy bits, find out what it can see, etc. Everyone goes on about Mythos but the real danger are companies putting everything in the cloud, without ACLs or with ACLs which don't work, and then letting Copilot loose on it. Forget lateral movement, just abuse the "collaborative, everyone must see everything to be productive with AI" myth! :flan_molotov:​

Replies (0)

No replies.