Microsoft Copilot Continues To Be A Nightmare
Our top stories this week:
- Microsoft Copilot reveals secret input that allowed it to be hacked
- Meta Patents AI Glasses to Use Facial Recognition to Identify People, Make Highlight Reels of Your Dinner Party
- Android 17 QPR2 adds App lock to Pixel
- A billion searches a year, now built in: Startpage comes to Firefox
- ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
TWIP Live 🔴
Updates from the Team
How To Make a Bitcoin Seed Phrase 🎲
Coinkite's Coldcard wallet recently suffered from a major, devastating flaw in its random number generation, exposing millions of dollars in Bitcoin held by their customers to attackers. We're going to show you how to generate a cryptocurrency seed phrase in the real world with only a 6-sided die, to guarantee our randomness isn't subject to an unknown software flaw.
News Briefs
This week was a busy week, with stories about how Microsoft is phasing out SMS 2FA in favor of passkeys, Meta's patent for facial recognition in their smart glasses, and of course our weekly data breach roundup.

Sources
Microsoft Copilot reveals secret input that allowed it to be hacked
While researching possible malicious uses of Microsoft Copilot, researchers at Varonis were able to eventually get Copilot to cough up the secret to autorunning commands. With this link, researchers were able to string together a series of malicious phishing attacks that should not have otherwise been possible. Microsoft has already patched the vulnerability, but it goes to show how AI agents can still be risky to use. X/Twitter's Grok was also subject to a similar attack, according to another set of researchers.


