#1
The Hacker News
general
August 18, 2026 at 17:47 UTC
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
By [email protected] (The Hacker News)
AI Summary
Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that allow a single crafted link click to silently exfiltrate data from connected apps available in the victim's Copilot session. The attack leverages an undocumented URL parameter that Copilot itself revealed during researcher interaction. Security practitioners using Microsoft 365 integrations should audit Copilot permissions and connected app access immediately.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →