Copilot Broke Your Audit Log, but Microsoft Won’t Tell You
Source evidence cited by public records. This page shows where the source is used, its trust tier, and when it was last checked in the seed.
Records using this source
- Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry
event | 4 Oct 2025 | 78%
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.