Feeds.4Sysops
Microsoft Copilot Vulnerability Exposed by Researchers in CoSnitch Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers at Varonis Threat Labs exploited a vulnerability in Microsoft Copilot Personal, tricking it into revealing sensitive data and allowing for unauthorized execution of commands via an undocumented URL parameter. This attack, named 'CoSnitch', involved social engineering techniques to manipulate the AI's reasoning engine into disclosing its own vulnerabilities without needing to reverse-engineer the system. The flaw could enable attackers to use a single phishing link or QR code to exfiltrate sensitive data and alter Copilot's memory. Microsoft was informed of the vulnerability in December 2025 and planned to issue a patch and formally identify the CVE on August 18, 2026. The researchers emphasized that the AI's own explanations led them to discover the undocumented parameter that facilitated the attack. The incident highlights significant risks associated with AI systems and their potential for exploitation.
Key Points: • Researchers exploited Microsoft Copilot to reveal sensitive data through social engineering. • The vulnerability, named 'CoSnitch', allows for unauthorized command execution via a hidden URL parameter. • Microsoft is set to release a patch for the vulnerability identified in December 2025.