Skip to main content

Tag: cosnitch

3 articles

Empty office setting with a laptop on a desk, screen facing away, surrounded by blurred office furniture and soft natural…

Microsoft Copilot Flaw Uncovered Through AI Model Manipulation

Researchers uncovered a concerning vulnerability in Microsoft Copilot, dubbed CoSnitch, which can be exploited with just one click to steal sensitive data without triggering obvious security alerts. The flaw was unusually revealed by Copilot itself during a normal interaction, highlighting the need for organizations to treat AI assistants with greater caution and scrutiny.

Analyst 207
Laptop on a desk with a blurred background and a suspicious link on paper.

Microsoft Copilot Flaws Expose One-Click Data Exfiltration Risk

Researchers uncovered a set of flaws in Microsoft Copilot, dubbed CoSnitch, that could allow attackers to exploit a user's session with just one click, potentially leading to data exfiltration. A single crafted link could trigger actions inside a signed-in user's assistant session, putting sensitive information at risk.

Analyst 207
Researcher in modern lab looks at laptop screen with concern.

Microsoft Copilot Exposes Vulnerability to Meta-Hacking

Researchers at Varonis Threat Labs uncovered a vulnerability in Microsoft Copilot, cleverly manipulating it to reveal its own weaknesses and craft a working attack, which they've dubbed CoSnitch. This surprising exploit was responsibly disclosed to Microsoft, which plans to issue a patch.

Analyst 207