What happened
Attacker sends a specially crafted email with hidden prompt payload; Copilot's RAG engine retrieves it during a subsequent user query and executes the payload, exfiltrating emails, Teams messages, OneDrive files, and SharePoint documents to attacker-controlled endpoints via rendered markdown links and images.