Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration
Executive Summary
Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, dubbed CoSnitch, that enable a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws exploit an undocumented URL parameter surfaced by the assistant itself.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-18T17:47:22+00:00 - Category: threat-intel
"We must not say every mistake is a foolish one."
— Cicero
Source: The Hacker News