Home / Aug 19, 2026 / Story
0
#1 The Hacker News general August 18, 2026 at 17:47 UTC

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

By [email protected] (The Hacker News)

AI Summary

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that allow a single crafted link click to silently exfiltrate data from connected apps available in the victim's Copilot session. The attack leverages an undocumented URL parameter that Copilot itself revealed during researcher interaction. Security practitioners using Microsoft 365 integrations should audit Copilot permissions and connected app access immediately.

Relevance score: 88.0/100

# More from August 19