Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now

NYT Connections Sports Edition Today: Hints and Answers for Sunday, September 14, 2025

Weapons, Honey Don’t, and every new movie on streaming this week

Amazon Has a 'Pretty' Pair of Puma Club Sneakers on Sale for Only $41 

Numbrix 9 – September 14

Why Personalized, Interactive Digital Experiences Are The Future

10 of the best things to do in and around Vancouver this week (Sept. 15-19)

Zach Bryan Physically Hops Over a Barbed-Wire Fence To Confront Gavin Adcock Amid Feud

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw Canada reviews
Reviews

Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw Canada reviews

6 August 20253 Mins Read

Researchers have already found a critical vulnerability in the new NLWeb protocol Microsoft made a big deal about just just a few months ago at Build. It’s a protocol that’s supposed to be “HTML for the Agentic Web,” offering ChatGPT-like search to any website or app. Discovery of the embarrassing security flaw comes in the early stages of Microsoft deploying NLWeb with customers like Shopify, Snowlake, and TripAdvisor.

The flaw allows any remote users to read sensitive files, including system configuration files and even OpenAI or Gemini API keys. What’s worse is that it’s a classic path traversal flaw, meaning it’s as easy to exploit as visiting a malformed URL. Microsoft has patched the flaw, but it raises questions about how something as basic as this wasn’t picked up in Microsoft’s big new focus on security.

“This case study serves as a critical reminder that as we build new AI-powered systems, we must re-evaluate the impact of classic vulnerabilities, which now have the potential to compromise not just servers, but the ‘brains’ of AI agents themselves,” says Aonan Guan, one of the security researchers (alongside Lei Wang) that reported the flaw to Microsoft. Guan is a senior cloud security engineer at Wyze (yes, that Wyze) but this research was conducted independently.

Guan and Wang reported the flaw to Microsoft on May 28th, just weeks after NLWeb was unveiled. Microsoft issued a fix on July 1st, but has not issued a CVE for the issue — an industry standard for classifying vulnerabilities. The security researchers have been pushing Microsoft to issue a CVE, but the company has been reluctant to do so. A CVE would alert more people to the fix and allow people to track it more closely, even if NLWeb isn’t widely used yet.

“This issue was responsibly reported and we have updated the open-source repository,” says Microsoft spokesperson Ben Hope, in a statement to The Verge. “Microsoft does not use the impacted code in any of our products. Customers using the repository are automatically protected.”

Guan says NLWeb users “must pull and vend a new build version to eliminate the flaw,” otherwise any public-facing NLWeb deployment “remains vulnerable to unauthenticated reading of .env files containing API keys.”

While leaking an .env file in a web application is serious enough, Guan argues it’s “catastrophic” for an AI agent. “These files contain API keys for LLMs like GPT-4, which are the agent’s cognitive engine,” says Guan. “An attacker doesn’t just steal a credential; they steal the agent’s ability to think, reason, and act, potentially leading to massive financial loss from API abuse or the creation of a malicious clone.”

Microsoft is also pushing ahead with native support for Model Context Protocol (MCP) in Windows, all while security researchers have warned of the risks of MCP in recent months. If the NLWeb flaw is anything to go by, Microsoft will need to take an extra careful approach of balancing the speed of rolling out new AI features versus sticking to security being the number one priority.

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

Liam Hemsworth is Geralt in the first Witcher season 4 trailer Canada reviews

Reviews 13 September 2025

Women Wearing Shoulder Pads’ creators did it for the culture Canada reviews

Reviews 13 September 2025

Exit 8’s director was inspired by watching people play the game Canada reviews

Reviews 13 September 2025

“Dead Man’s Wire” Excels in its Underdog Wiring of Deadly Wit and Electricity – front mezz junkies, Theater News

Reviews 13 September 2025

Tucker Carlson asks Sam Altman if an OpenAI employee was murdered ‘on your orders’ Canada reviews

Reviews 12 September 2025

Elon Musk is trying to silence Microsoft employees who criticize Charlie Kirk Canada reviews

Reviews 12 September 2025
Top Articles

The ocean’s ‘sparkly glow’: Here’s where to witness bioluminescence in B.C. 

14 August 2025274 Views

These Ontario employers were just ranked among best in Canada

17 July 2025268 Views

Getting a taste of Maori culture in New Zealand’s overlooked Auckland | Canada Voices

12 July 2025138 Views

The Mother May I Story – Chickpea Edition

18 May 202496 Views
Demo
Don't Miss
What's On 14 September 2025

10 of the best things to do in and around Vancouver this week (Sept. 15-19)

Buckle up for tons of live music options this week, Vancouver! Whether you’re a Jonas…

Zach Bryan Physically Hops Over a Barbed-Wire Fence To Confront Gavin Adcock Amid Feud

Sounds Good Moving Redefines Relocation in Victoria, BCFOR IMMEDIATE RELEASE – Scoop Canada

Today’s NYT ‘Strands’ Hints, Spangram and Answers for Sunday, September 14

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

NYT Connections Sports Edition Today: Hints and Answers for Sunday, September 14, 2025

Weapons, Honey Don’t, and every new movie on streaming this week

Amazon Has a 'Pretty' Pair of Puma Club Sneakers on Sale for Only $41 

Most Popular

Why You Should Consider Investing with IC Markets

28 April 202424 Views

OANDA Review – Low costs and no deposit requirements

28 April 2024345 Views

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202449 Views
© 2025 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.