Security researchers at Varonis Threat Labs disclosed “Reprompt,” a prompt-injection attack against Microsoft Copilot Personal that could let an attacker exfiltrate a victim’s conversation history and OneDrive data after a single click on a crafted link. The attack chained a malicious URL parameter with a technique that repeated hidden instructions to bypass Copilot’s built-in safeguards, and it kept working even after the victim closed the chat window. Researchers found no evidence the flaw was exploited in the wild before Microsoft addressed it following responsible disclosure. Enterprise users of Microsoft 365 Copilot were not affected.