Varonis Threat Labs discovered a critical vulnerability in Microsoft Copilot Personal, dubbed CoSnitch, which allows attackers to exfiltrate sensitive user data and poison persistent memory. By employing a 'meta-hacking' technique, researchers tricked the AI into revealing an undocumented parameter, `autorun=1`. This parameter enables automatic prompt execution via crafted URLs without user interaction, exposing emails, credentials, and connected applications.
Oct 2, 2026 · 6 sources
Oct 1, 2026 · 3 sources
Oct 1, 2026 · 2 sources
Sep 30, 2026 · 3 sources
Story comments
Loading comments…