Microsoft Copilot Personal flaws allow one-click data exfiltration

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could let a single click on a crafted link silently pull data from connected apps. Patches shipped on August 18, 2026, tracked as CVE-2026-24301.
1 source
Cybersecurity by email
Get an email when there's news on Cybersecurity
No news that day, no email.
More stories today
- Meta builds AI 'second brain' that learns from experts
- Snowflake shares surge 22% on AI coding momentum
- Gary Marcus critiques Musk's AI prediction shift
- Lutnick says Anthropic has patched relations with US government
- HPE lifts sales forecast on AI server demand