> From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
[DATE: 30/09/2026 21:00]
[LANGUAGE: EN]
Two weeks back I presented at BlueHat Asia 2026 about my research on Microsoft’s Copilot in SSMS, the SQL Server Management Studio.
This post is a write up about the talk, which covered CVE-2026-65669, a SQL Server Elevation of Privilege Vulnerability rated critical by Microsoft.
So, make sure your installations are up-to-date.
The slides of the presentation can be found here.
BlueHat Asia 2026 in Singapore
First, a few words about the conference. I have spoken at BlueHat before, sometime back in 2017, and also two years ago. Both times at Microsoft’s Redmond Campus.