What happens when an attacker gets a live, interactive shell inside Microsoft 365 Copilot?
@vbCrLf from Rubrik Zero Labs dropped ChatMate, the first publicly documented Remote Prompt Execution (RPE): an attacker manipulating a victim's assistant, prompt by prompt.
I found a PreAuth RCE chain in GeoNetwork, which is used by many Governments, Internacional Orgs and military across the globe to catalog geospatial data. Here's the writeup about it, hope you enjoy it :)
ethiack.com/info-hub/resea…