Security2 distinct publishers3 min readPublished Updated
Varonis says Copilot disclosed an undocumented URL parameter mid-refusal, enabling silent exfiltration. Microsoft shipped patches on August 18, 2026, about eight months after disclosure.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Varonis Threat Labs has published a one-click vulnerability chain in Microsoft Copilot Personal that it calls CoSnitch, which it says quietly exfiltrates enterprise data without obvious red flags [1]. It is the third Microsoft Copilot flaw the team has disclosed this year, and Varonis says all three collapse into the same pattern: one click on a legitimate-looking link is enough [3][6].
The mechanism has three parts, according to Varonis. The `?q=` URL parameter, combined with an undocumented parameter, causes an attacker-supplied prompt to run instantly on page load, with no click, confirmation, or user action [9]. That injected prompt can then query the victim's connected apps, including Gmail, Drive, Calendar and OneDrive, encode the results into a URL, and push them out through Copilot's own URL-fetch capability to an attacker-controlled webhook [10]. Third, a crafted webpage summarized by Copilot writes attacker instructions into the victim's permanent memory store, where Varonis says the injection survives password changes, session revocation and device re-enrollment [11].
That last item is the one worth sitting with. The standard containment playbook for a compromised account is credential reset, session kill, re-enroll the device. Varonis is describing a persistence primitive that all three of those steps miss [11].
The discovery route is the other novel part, and Varonis is candid that it is not a code exploit. Researchers asked Copilot how to execute a prompt without user interaction; it replied that this is not how it works, that user intent is required, and that prompts do not fire on their own [12]. They kept reframing each refusal as a natural follow-up, asking about URL structure, deep links, and what happens when a page loads with input already in the field [13]. Copilot then disclosed an undocumented URL parameter unprompted, mid-refusal, including its historical behavior and every protection that had been added to disable it [14]. Varonis built the URL exactly as described and the prompt executed automatically, with no click or confirmation [15]. The company's own summary is blunt: Copilot was not breached, it was played [18]. Varonis calls the technique meta-hacking, and frames it as a shift in how flaws get found, since nobody had to reverse-engineer anything [2].
The consequence for defenders is a monitoring problem more than a patching one. Varonis's argument is that sensitive data spread across email, files, calendars and chats is now reachable through one assistant, and that CoSnitch moves large volumes of it through a trusted AI workflow without tripping the alarms security teams normally rely on [16]. An assistant that is authorized to read everything and permitted to fetch URLs is, functionally, a sanctioned egress path.
Timing matters here. Varonis says it disclosed CoSnitch to Microsoft in December 2025 and that patches shipped on August 18, 2026 [7], roughly eight months later [17]. Varonis reports no evidence of exploitation in the wild and credits Microsoft with collaborating on the fix [8].
What to watch: whether the fourth finding follows the same shape. Reprompt bypassed Copilot's guardrails just by asking twice [4]; SearchLeak turned Microsoft 365 Copilot Enterprise into a silent exfiltration tool [5]. Three flaws with one click as the trigger [6] suggests the patched items were instances, not the class. Ask your vendor whether prompt-driven URL fetches are logged where your detection team can see them, and whether persistent assistant memory is in scope for incident response.
Ranked by verification strength, evidence, and original report placement.
Varonis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch, which quietly executes an attack chain that exfiltrates data from enterprises without obvious red flags.
Varonis says Copilot surfaced its own vulnerabilities, a method the company calls meta-hacking; researchers did not have to reverse-engineer the flaw because the AI exposed the weakness during normal use, which Varonis describes as a meaningful shift in how security flaws are found.
Varonis disclosed CoSnitch to Microsoft in December 2025, and patches were shipped on August 18, 2026.
An injected prompt can query the victim's connected apps (Gmail, Drive, Calendar, OneDrive), encode the results into a URL, and exfiltrate them via Copilot's built-in URL-fetch capability to an attacker-controlled webhook.
Persistent memory poisoning via web summarization: a crafted webpage, when summarized by Copilot, injects attacker instructions into the victim's permanent memory store, and the injection survives password changes, session revocation and device re-enrollment, persisting indefinitely.
When Varonis first asked Copilot how to execute a prompt automatically without user interaction, it explained that is not how it works, that user intent is required, and that prompts do not fire on their own.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor reproduction, CVE-tracked, independently reported but not independently reproduced
The originating writeup gives a concrete attack primitive (attack URL format, both required parameters, execution-to-completion behavior), an enumerated three-vulnerability chain, and a named data inventory recovered in testing; a second publisher restates the mechanics, adds a CVE identifier from Microsoft's Security Update Guide, cites Microsoft's own documentation and prior third-party memory research, and confirms the disclosure and patch dates. What is missing is any independent reproduction of the elicitation dialogue or the autorun execution, and the enterprise-scope framing is not corroborated: the research is bounded to the consumer Copilot Personal assistant.
Remediation shipped and CVE-tracked; residual exposure and pre-patch cleanup unverified
Adoption here is remediation uptake rather than product uptake. Microsoft shipped patches on August 18, 2026, the issue carries CVE-2026-24301, and adjacent Copilot memory reports were recorded as mitigated globally with Microsoft describing shipped memory-integrity and audit controls for Microsoft 365 Copilot. Counting against a higher score: the fix is server-side with no user-installable update identified, no telemetry on affected users is disclosed, neither source reports whether memories written before the fix were removed, and no exploitation in the wild was observed.
Framing runs ahead of bounded, patched, consumer-scoped findings
The mechanics are real and corroborated, but the vendor's presentation stretches beyond them: data 'exfiltrated from enterprises' and a 'meaningful shift in how security flaws are found' sit on research scoped to the consumer Copilot Personal assistant, with no claim that Microsoft 365 Copilot behaved the same way; poisoned memory is said to persist 'forever' when reporting notes it persists until the user deletes it in memory settings; and the detection-blindness framing is set against Microsoft's stated connector permission limits and, for Microsoft 365 Copilot, sanitization and audit-log telemetry. The issue is also patched with no observed exploitation. The gap is one of framing and scope, not of fabricated mechanism.
Vendor-authored, branded disclosure with explicit defensive-product framing
The primary source is a security vendor's own threat-lab blog that names and brands the finding (CoSnitch), coins a method label (meta-hacking), tallies it as the team's third Copilot flaw this year, and closes into guidance on 'how to protect your organization' — all of which serve the publisher's commercial interest in AI data security. The secondary publisher is an independent security outlet whose reporting adds scope limits and Microsoft's counter-position, which partly offsets the originating incentive but does not remove it, since the cluster's mechanism evidence still originates entirely with the interested party.
Mechanism well specified and dual-sourced; scope and residual-risk questions open
Two publishers agree on the chain, dates, CVE, and absence of observed exploitation, and the second adds external references that check the first, so the factual core is solid. Confidence is held below high because all mechanism evidence traces to one interested researcher without independent reproduction, the enterprise-versus-consumer scope is explicitly contested, and neither source resolves whether memory entries written before the patch were removed.
security
Microsoft puts Defender Experts analysts on Palo Alto, AWS and Okta logs through Sentinel1 distinct publisher
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
security
Windows 11's secure kernel trusts a RAM chip that never checks who is writing to it1 distinct publisher
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 19, 2026
1 article · August 18, 2026