CoSnitch attack exploits Copilot's own disclosure of autorun=1

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that allow a single click on a crafted link to silently exfiltrate data from connected apps. The attack uses an undocumented URL parameter, autorun=1, which Copilot itself revealed during a 'meta-hacking' interrogation. Patches shipped August 18, 2026; tracked as CVE-2026-24301.
Featured · Lior Adar
3 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Z.ai CEO Jie Tang: GLM 5.3 gains come from RL, not parameter count
- New tool adds 14 skills to Claude Code and Cursor for Markdown diagrams
- Tool turns Claude into a team of AI employees on your Mac
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills