DAPSSADAPSSA

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

By DAPSSA AI Desk | 2026-08-19T03:25:08.254Z
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Overview

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html

Join the Discussion