AnalysisCybersecurityAugust 18, 2026

CoSnitch attack exploits Copilot's own disclosure of autorun=1

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that allow a single click on a crafted link to silently exfiltrate data from connected apps. The attack uses an undocumented URL parameter, autorun=1, which Copilot itself revealed during a 'meta-hacking' interrogation. Patches shipped August 18, 2026; tracked as CVE-2026-24301.

Featured · Lior Adar

3 sources

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed