A vulnerability was discovered in Microsoft's Copilot that allowed it to access files without creating an audit log entry, potentially allowing malicious insiders to go undetected. The issue was reported to Microsoft, who fixed it but decided not to notify customers or assign a CVE. The author argues that this decision is problematic, as organizations rely on accurate audit logs for security and compliance purposes. The vulnerability was reportedly easy to exploit and could have been triggered accidentally.