Episode Details
Back to Episodes
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
Description
This story was originally published on HackerNoon at: https://hackernoon.com/cosnitch-when-your-ai-assistant-becomes-its-own-whistleblower.
CoSnitch exposed a critical Microsoft Copilot flaw that enabled one-click prompt execution, data exfiltration, and persistent memory poisoning.
Check more stories related to undefined at: https://hackernoon.com/c/undefined.
You can also check exclusive content about #cosnitch, #microsoft-copilot-security, #copilot-data-exfiltration, #ai-assistant-security, #meta-hacking, #ai-prompt-injection, #indirect-prompt-injection, #good-company, and more.
This story was written by: @varonis. Learn more about this writer by checking @varonis's about page,
and for more stories, please visit hackernoon.com.
Varonis Threat Labs uncovered CoSnitch, a critical Microsoft Copilot vulnerability tracked as CVE-2026-24301. A crafted link could automatically execute an attacker-controlled prompt, access data through connected apps, exfiltrate information through Copilot’s URL-fetch capability, and modify persistent memory through indirect prompt injection. The research also introduces “meta-hacking,” where Copilot’s own responses helped researchers uncover its attack surface.