Opening SecureFlowCopirate 365: Persistent Memory-Backdoor Data Exfiltration in Microsoft 365 Copilot (CVE-2026-24299)
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Embrace The Red (Johann Rehberger) aidefend-sf0005

Copirate 365: Persistent Memory-Backdoor Data Exfiltration in Microsoft 365 Copilot (CVE-2026-24299)

  • Copilot & SaaS
  • Autonomous Agents
  • Data Exfiltration
  • Model Poisoning & Integrity

A validated research flow showing how a poisoned document, Delayed Tool Invocation, and a record_memory write build a persistent Microsoft 365 Copilot backdoor that exfiltrates pasted secrets every future session through a CSS font-face URL that evades the image-src CSP.

Mapped threat techniques

Source