Back Feeds.4Sysops Microsoft Copilot flaw turned one click into silent data theft
A hidden `?autorun=1` parameter allowed attackers to bypass Microsoft Copilot’s prompt-approval safeguard and run commands inside a victim’s authenticated session. Varonis Threat Labs dubbed the issue CoSnitch and tracked it as CVE-2026-32193; Microsoft plans to remove the undocumented behavior. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
