Connect with us

Hi, what are you looking for?

Top Stories

Security Flaw Exposes Sensitive Emails in Microsoft 365 Copilot

A significant security flaw in Microsoft 365 Copilot has been identified, allowing the AI assistant to mistakenly summarize email messages that are protected by confidentiality labels, thereby circumventing established Data Loss Prevention (DLP) policies. This issue, tracked under Microsoft reference CW1226324, was first reported on February 4, 2026, and continues to pose risks to sensitive organizational data.

The Copilot feature, particularly the “Work Tab” Chat function, is actively producing summaries of confidential emails. This occurs even when DLP policies are set specifically to prohibit such processing. The incident report indicates that the flaw allows Copilot to access items in users’ Sent Items and Draft folders, effectively bypassing the confidentiality protections that should be in place.

Technical Details and Industry Concerns

Microsoft’s internal investigation revealed that a code-level defect is the root cause of this issue. Under normal circumstances, sensitivity labels, when combined with DLP policies, would prevent Copilot from processing emails marked as confidential. The existence of this bug renders those controls ineffective for certain folders, exposing restricted content in AI-generated summaries.

This situation is particularly alarming for organizations in regulated sectors, such as healthcare, finance, and government. For these entities, maintaining email confidentiality is not just a best practice; it is a matter of compliance with legal obligations. The NHS has flagged the incident internally as INC46740412, underscoring its potential impact on public sector users who rely on Microsoft 365.

As of February 11, 2026, Microsoft has started to deploy a fix across affected environments and is contacting a subset of impacted users to gauge the effectiveness of the remediation. However, the rollout remains incomplete, and the issue persists for some organizations. Microsoft has committed to providing a remediation timeline as the situation evolves.

Implications for Organizations and Next Steps

The implications of this flaw are broad, affecting any organization using Microsoft 365 Copilot with confidentiality labels on their emails. Administrators are advised to monitor the Microsoft 365 admin center for updates related to reference CW1226324 and to scrutinize Copilot activity logs for any unusual access to sensitive content.

The ability of the AI assistant to bypass DLP policies indicates a critical security gap. DLP controls are fundamental to enterprise data governance, and any tool, AI or otherwise, that can circumvent these controls undermines the security framework of an organization. Until a comprehensive fix is fully deployed, security teams may need to consider restricting Copilot access in environments that manage highly sensitive email communications.

Microsoft is expected to provide further updates on this matter by February 18, 2026, at 11:00 AM UTC. For ongoing cybersecurity updates, users can follow the organization on platforms such as Google News, LinkedIn, and X.

This incident serves as a reminder of the complexities involved in managing AI tools within corporate environments, particularly when sensitive data is at stake.

You May Also Like

Entertainment

The 15th annual Friends of the Library of Hawaiʻi Music & Book Sale took place on January 18, 2026, at Ward Centre in Honolulu,...

World

U.S. futures experienced a decline on Monday as markets across Asia showed notable gains. This shift occurred after Federal Reserve Chair Jerome Powell revealed...

World

The U.S. Department of War marked the transition from 2025 to 2026 with significant updates, culminating in the historic capture of Venezuelan leader Nicolás...

Sports

Jacob Laverman has transformed his early life on a farm in Ocheyedan, Iowa, into a thriving career in sports medicine, culminating in a prominent...

Health

New dietary guidelines issued by the U.S. Department of Health and Human Services are urging parents to limit added sugars in their children’s diets...

Health

A long-term study has uncovered that significant declines in physical fitness and strength commence around age 35 and persist through midlife. The research, conducted...

Sports

Following a gripping match on December 29, 2023, episode of WWE RAW, Nikki Bella took the opportunity to clarify the distinctiveness of her submission...

Top Stories

URGENT UPDATE: A vintage stoplight has been stolen from a home in Guthrie, and the owners are in a race against time to recover...

World

American Airlines has announced plans to resume nonstop flights from the United States to Venezuela, marking a significant move as the first U.S. airline...

Top Stories

UPDATE: Major revelations about the highly anticipated second season of Heated Rivalry have just surfaced, igniting excitement among fans eager to see how the...

Top Stories

UPDATE: The highly anticipated Rose Bowl featuring the Alabama Crimson Tide against the Indiana Hoosiers kicks off today at 4:00 PM ET in Pasadena,...

Education

After a prolonged budget impasse, Pennsylvania’s school districts are set to benefit from a newly adopted state budget of $50.09 billion, which includes substantial...

Business

The ATAC Credit Rotation ETF (NYSEARCA:JOJO) experienced an impressive decline in short interest, dropping by an astounding 89.5% in January 2024. As of January...

Politics

The Undergraduate Senate (UGS) has unanimously passed several significant bills aimed at reforming funding for student organizations and clarifying the governance of class presidents...

Top Stories

URGENT UPDATE: Supreme Court Justice Antonin Scalia, a pivotal figure in American jurisprudence, was found dead today, February 13, 2016, at a private residence...

Top Stories

BREAKING: Seven-time Grand Slam champion Venus Williams is set to return to the Australian Open in Melbourne after a five-year hiatus. At the age...

Copyright © All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site.