FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Microsoft's AI Read Executives' Confidential Emails for a Month. Microsoft's Security Tools Were Supposed to Stop It.
How-ToSecurity

Microsoft's AI Read Executives' Confidential Emails for a Month. Microsoft's Security Tools Were Supposed to Stop It.

via Dev.toMoth3w ago

A bug tracked as CW1226324 allowed Microsoft 365 Copilot to bypass Data Loss Prevention policies and summarize emails marked "Confidential" in users' Sent Items and Drafts folders. The flaw was active from at least January 21, 2026. Microsoft disclosed it publicly in mid-February and began rolling out a patch — nearly a month after the breach started. The setup is almost too on-the-nose. Enterprise customers pay Microsoft for two products that are supposed to work together. The first is Microsoft Information Protection, which applies sensitivity labels — "Confidential," "Highly Confidential," "Internal Only" — to documents and emails. The second is Copilot, the AI assistant embedded across Microsoft 365 that reads, summarizes, and acts on enterprise data. The entire selling proposition of DLP is that it governs what Copilot can see. When a CISO tags a board compensation memo as "Confidential," the expectation is that Copilot can't index it, summarize it, or surface it in a colleague's

Continue reading on Dev.to

Opens in a new tab

Read Full Article
25 views

Related Articles

What we’re looking for in Startup Battlefield 2026 and how to put your best application forward
How-To

What we’re looking for in Startup Battlefield 2026 and how to put your best application forward

TechCrunch • 1d ago

Build Days That Actually Mean Something
How-To

Build Days That Actually Mean Something

Medium Programming • 1d ago

I have blogged about the difference between code coverage and test coverage and why it matters to distinguish between these 2.
How-To

I have blogged about the difference between code coverage and test coverage and why it matters to distinguish between these 2.

Dev.to Beginners • 1d ago

The origin story of Apple’s long-running relationship with FoxConn
How-To

The origin story of Apple’s long-running relationship with FoxConn

The Verge • 1d ago

How to Optimize Big Data Platform Costs Across the Data Lifecycle
How-To

How to Optimize Big Data Platform Costs Across the Data Lifecycle

Hackernoon • 1d ago

Discover More Articles