Copilot’s screen-snapping feature allows users to recall data stored in plain text

Published:

spot_img

Safety Implications of Microsoft’s Recall Feature: Researchers Warn of Cybersecurity Setback

In a shocking revelation, cybersecurity researchers have raised serious concerns about Microsoft’s Recall feature, claiming that it poses a significant threat to user privacy and cybersecurity. The Recall feature, which captures screenshots of everything users do on their devices, has been criticized for storing this sensitive information on an SQLite database that can be easily accessed by anyone with administrator-level privileges.

Kevin Beaumont, a renowned cybersecurity researcher, has highlighted the potential risks associated with Recall, stating that attackers could easily exfiltrate the data stored in the database. Despite Microsoft’s assurances that remote access to the screenshots is not possible, Beaumont has demonstrated how attackers could exploit this feature to steal sensitive information from users.

Furthermore, Beaumont tested Recall with popular messaging apps like WhatsApp, Signal, and Teams, revealing that the feature captures conversations, including disappearing messages and deleted content. This raises serious concerns about user privacy and the security of sensitive communications.

Microsoft introduced Recall as part of its new AI-driven personal computers, Copilot+, with CEO Satya Nadella likening the feature to the device’s “photographic memory.” However, cybersecurity experts warn that Recall could potentially set cybersecurity back by a decade and empower cybercriminals to exploit users’ data for malicious purposes.

As the debate around Microsoft’s Recall feature continues to escalate, users are urged to exercise caution and be vigilant about their online activities to protect their privacy and security in an increasingly digital world.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...