Close Menu
Breaking News in Technology & Business – Tech Geekwire

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Startup TwinMind Launches ‘Proactive’ AI App to Optimize Users’ Lives

    May 13, 2025

    IBM Introduces LinuxONE Emperor 5: A Mainframe for AI

    May 13, 2025

    Telstra Health Announces New Partnerships to Enhance Digital Health Ecosystem

    May 13, 2025
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech GeekwireBreaking News in Technology & Business – Tech Geekwire
    • New
      • Amazon
      • Digital Health Technology
      • Microsoft
      • Startup
    • AI
    • Corporation
    • Crypto
    • Event
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech Geekwire
    Home » Microsoft Copilot Still Exposes Private GitHub Repositories Despite Fix, Researchers Find
    Microsoft

    Microsoft Copilot Still Exposes Private GitHub Repositories Despite Fix, Researchers Find

    techgeekwireBy techgeekwireMarch 3, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email
    Screenshot showing Copilot continues to serve tools Microsoft took action to have removed from GitHub.
    Screenshot showing Copilot continues to serve tools Microsoft took action to have removed from GitHub.

    Security researchers at Lasso have found that Microsoft’s Copilot is still providing access to private GitHub repositories, even after Microsoft attempted to remove tools from public access. The issue stems from cached data that Copilot can access, even after it’s no longer available to human users.

    Lasso’s investigation revealed that Microsoft’s fix involved cutting off public access to a special Bing user interface that displayed cached pages. However, the fix didn’t fully remove the private pages from the cache itself, leaving them accessible to Copilot.

    “Although Bing’s cached link feature was disabled, cached pages continued to appear in search results,” Lasso explained. “This indicated that the fix was a temporary patch and while public access was blocked, the underlying data had not been fully removed.”

    When Lasso revisited their investigation, they confirmed their suspicions: Copilot still had access to the cached data, even though it was no longer available to human users. Making the code private isn’t enough to protect sensitive data, once exposed.

    Developers often embed sensitive information, such as security tokens and private encryption keys, directly into their code, despite best practices. This practice, commonly seen in public repositories, increases the risk of data breaches.

    Microsoft recently incurred legal expenses to have tools removed from GitHub, citing violations of several laws including the Computer Fraud and Abuse Act and the Digital Millennium Copyright Act. However, Copilot continues to undermine this work by making the tools available.

    In a statement emailed after the discovery went live, Microsoft said, “It is commonly understood that large language models are often trained on publicly available information from the web. If users prefer to avoid making their content publicly available for training these models, they are encouraged to keep their repositories private at all times.”

    Copilot data breach GitHub Microsoft security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techgeekwire
    • Website

    Related Posts

    Startup TwinMind Launches ‘Proactive’ AI App to Optimize Users’ Lives

    May 13, 2025

    IBM Introduces LinuxONE Emperor 5: A Mainframe for AI

    May 13, 2025

    Telstra Health Announces New Partnerships to Enhance Digital Health Ecosystem

    May 13, 2025

    Amazon to Introduce Advertisements on Prime Video from June 17

    May 13, 2025

    Amazon Prime Video to Introduce Ads in India from June 17, 2025

    May 13, 2025

    Navigation Menu for News Website

    May 13, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Startup TwinMind Launches ‘Proactive’ AI App to Optimize Users’ Lives

    May 13, 2025

    IBM Introduces LinuxONE Emperor 5: A Mainframe for AI

    May 13, 2025

    Telstra Health Announces New Partnerships to Enhance Digital Health Ecosystem

    May 13, 2025

    Amazon to Introduce Advertisements on Prime Video from June 17

    May 13, 2025
    Advertisement
    Demo
    About Us
    About Us

    A rich source of news about the latest technologies in the world. Compiled in the most detailed and accurate manner in the fastest way globally. Please follow us to receive the earliest notification

    We're accepting new partnerships right now.

    Email Us: info@example.com
    Contact: +1-320-0123-451

    Our Picks

    Startup TwinMind Launches ‘Proactive’ AI App to Optimize Users’ Lives

    May 13, 2025

    IBM Introduces LinuxONE Emperor 5: A Mainframe for AI

    May 13, 2025

    Telstra Health Announces New Partnerships to Enhance Digital Health Ecosystem

    May 13, 2025
    Categories
    • AI (2,017)
    • Amazon (814)
    • Corporation (779)
    • Crypto (888)
    • Digital Health Technology (811)
    • Event (422)
    • Microsoft (975)
    • New (7,220)
    • Startup (814)
    © 2025 TechGeekWire. Designed by TechGeekWire.
    • Home

    Type above and press Enter to search. Press Esc to cancel.