The attack technique involves redirecting requests to the IMDS, enabling the retrieval of managed identity access tokens.
Originally appeared here:
Critical server-side vulnerability in Microsoft Copilot Studio gives illegal access to internal infrastructure