preloader

· · digital-security microsoft copilot ai-security cve data-privacy prompt-injection europe vulnerability-management

Researchers Got Microsoft Copilot to Explain Exactly How to Hack Itself

Source: The Hacker News

The safest way to keep a secret is to never explain why it is safe. Microsoft Copilot did not get that memo.

A one-click flaw called CoSnitch

CoSnitch, tracked as CVE-2026-24301, affected Microsoft Copilot Personal and could be triggered with nothing more than a victim clicking a single malicious link. From there it silently pulled sensitive data out of the victim’s connected accounts, no follow-up interaction required. Varonis Threat Labs reported it to Microsoft in December 2025, and Microsoft says it found no evidence the flaw was exploited before the patch shipped on August 18, 2026, which still leaves an eight-month gap between disclosure and fix for a bug rated critical.

How researchers found it: they asked the AI to prove them wrong

The detail that makes CoSnitch worth reading about is the discovery method. Varonis researchers asked Copilot to explain why a suspected attack path would not work. Copilot’s own explanation, intended to demonstrate the exploit was infeasible, ended up describing its internal architecture in enough detail to reveal the exact undocumented parameter an attacker would need. Varonis calls this “meta-hacking”: rather than attacking Copilot’s code, you social-engineer its reasoning process into handing you the blueprint. It is a very different failure mode from a traditional buffer overflow or injection bug, and it is one that conventional code review will not catch.

Not a one-off

CoSnitch is the third Copilot vulnerability Varonis has disclosed in 2026, following Reprompt, which bypassed Copilot’s safety guardrails simply by asking the same question twice, and SearchLeak, which turned Microsoft 365 Copilot Enterprise into a covert exfiltration channel. Three distinct bypasses in one product line in one year is a pattern, not a coincidence, and it says something specific about how AI assistants fail: their guardrails are reasoning-based, and reasoning can be talked around in ways a firewall rule cannot.

What this means if Copilot touches your business

European organisations that have rolled out Microsoft 365 Copilot or Copilot Personal are trusting it with access to email, files, and other connected accounts. Traditional application security testing was not built to probe for this class of flaw, where the vulnerability lives in what the model will say rather than in a line of exploitable code. If your AI assistant deployment has not had its guardrails, connected-account scopes, and prompt-handling behaviour independently reviewed, CoSnitch is a preview of the kind of gap that review would need to find.

If you want your Copilot or other AI assistant rollout assessed for this kind of exposure, or need help defining what data these tools should and should not be allowed to touch, contact Excello Digital. We help European businesses adopt AI tools without adopting their blind spots.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!