By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release

Google Pixel 10, Pixel 10 Pro XL Renders Leaked; New Lineup Said to Offer Camera Coach Feature

News Room News Room 7 August 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw
News

Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw

News Room
Last updated: 6 August 2025 14:22
By News Room 4 Min Read
Share
SHARE

Researchers have already found a critical vulnerability in the new NLWeb protocol Microsoft made a big deal about just just a few months ago at Build. It’s a protocol that’s supposed to be “HTML for the Agentic Web,” offering ChatGPT-like search to any website or app. Discovery of the embarrassing security flaw comes in the early stages of Microsoft deploying NLWeb with customers like Shopify, Snowlake, and TripAdvisor.

The flaw allows any remote users to read sensitive files, including system configuration files and even OpenAI or Gemini API keys. What’s worse is that it’s a classic path traversal flaw, meaning it’s as easy to exploit as visiting a malformed URL. Microsoft has patched the flaw, but it raises questions about how something as basic as this wasn’t picked up in Microsoft’s big new focus on security.

“This case study serves as a critical reminder that as we build new AI-powered systems, we must re-evaluate the impact of classic vulnerabilities, which now have the potential to compromise not just servers, but the ‘brains’ of AI agents themselves,” says Aonan Guan, one of the security researchers (alongside Lei Wang) that reported the flaw to Microsoft. Guan is a senior cloud security engineer at Wyze (yes, that Wyze) but this research was conducted independently.

Guan and Wang reported the flaw to Microsoft on May 28th, just weeks after NLWeb was unveiled. Microsoft issued a fix on July 1st, but has not issued a CVE for the issue — an industry standard for classifying vulnerabilities. The security researchers have been pushing Microsoft to issue a CVE, but the company has been reluctant to do so. A CVE would alert more people to the fix and allow people to track it more closely, even if NLWeb isn’t widely used yet.

“This issue was responsibly reported and we have updated the open-source repository,” says Microsoft spokesperson Ben Hope, in a statement to The Verge. “Microsoft does not use the impacted code in any of our products. Customers using the repository are automatically protected.”

Guan says NLWeb users “must pull and vend a new build version to eliminate the flaw,” otherwise any public-facing NLWeb deployment “remains vulnerable to unauthenticated reading of .env files containing API keys.”

While leaking an .env file in a web application is serious enough, Guan argues it’s “catastrophic” for an AI agent. “These files contain API keys for LLMs like GPT-4, which are the agent’s cognitive engine,” says Guan. “An attacker doesn’t just steal a credential; they steal the agent’s ability to think, reason, and act, potentially leading to massive financial loss from API abuse or the creation of a malicious clone.”

Microsoft is also pushing ahead with native support for Model Context Protocol (MCP) in Windows, all while security researchers have warned of the risks of MCP in recent months. If the NLWeb flaw is anything to go by, Microsoft will need to take an extra careful approach of balancing the speed of rolling out new AI features versus sticking to security being the number one priority.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

World of Warcraft Players Say Newest Patch Has a Lot of Weird Bugs, Including One That’s Turning Everyone’s Banks German

News Room News Room 7 August 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

The Internet’s Biggest Travel Nerd Shares Pointers on Points

Is that how the blog started—a passion for sharing the fine print?When I lived in…

7 August 2025

Get Batman: Arkham City, Shadow of Mordor, and 14 more games for $12

This bittersweet bundle features an array of licensed and original open-world titles, fighting games, and…

7 August 2025

Guilty Gear Strive Producer On Lucy, Upcoming Balance Changes, and Strive 2.00

More than four years after it's release, Guilty Gear Strive is still going strong, with…

7 August 2025
News

Want a Different Kind of Work Trip? Try a Robot Hotel

The decision to employ robots across Henn na’s portfolio “is made on a case-by-case basis depending upon location and market conditions,” according to spokeswoman Mami Matsumoto.Generally, Henn na’s robots can…

News Room 7 August 2025

Your may also like!

Mobile

Samsung Galaxy A17 5G With Exynos 1330 SoC Launched: Price, Specifications

News Room 7 August 2025
News

Combating Domestic Violent Extremism Is No Longer a FEMA Priority

News Room 7 August 2025
News

Apple announces $100 billion US manufacturing plan after pressure from Donald Trump

News Room 7 August 2025
News

16 Golden Rules That Business Travelers Swear By

News Room 7 August 2025

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?