Remote Prompt Execution Is a New Vulnerability Class. ChatMate Just Showed How It Works on Copilot.
At Black Hat USA 2026, researchers Ori Lahav and Dan Avraham of Rubrik Zero Labs detailed a new vulnerability class termed Remote Prompt Execution (RPE). The demonstration focused on Microsoft 365 Copilot, showing how a five-stage exploit chain can transform a standard prompt injection into a persistent, bidirectional interactive shell. The underlying vulnerability, CVE-2026-32193, is…