Varonis Threat Labs discovered a critical vulnerability in Microsoft Copilot Personal, dubbed CoSnitch, which allows attackers to exfiltrate sensitive user data and poison persistent memory. By employing a 'meta-hacking' technique, researchers tricked the AI into revealing an undocumented parameter, `autorun=1`. This parameter enables automatic prompt execution via crafted URLs without user interaction, exposing emails, credentials, and connected applications.
Aug 19, 2026 · 5 sources
Aug 17, 2026 · 4 sources
Aug 19, 2026 · 4 sources
Aug 18, 2026 · 3 sources
Story comments
Loading comments…