Security researchers at Varonis uncovered CoSnitch, a critical one-click vulnerability in Microsoft Copilot Personal that could enable silent data exfiltration.
What makes the discovery unusual is how researchers found it. Instead of relying solely on conventional reverse engineering, they repeatedly questioned Copilot about why a proposed attack would not work. Its explanations gradually exposed architectural details that helped researchers uncover the weakness—a technique Varonis calls “meta-hacking.”
The attack chain combined three weaknesses involving automatic prompt execution, access to data through connected applications, and persistent-memory manipulation. A malicious link could potentially trigger actions within an authenticated Copilot session.
Varonis disclosed the vulnerability to Microsoft in December 2025. Microsoft shipped patches on August 18, 2026, and Varonis said it found no evidence of exploitation in the wild.
The discovery highlights a new AI-security challenge: an assistant’s reasoning can itself reveal clues about its attack surface. As copilots gain access to email, files and connected applications, enterprises must increasingly treat AI assistants as privileged identities requiring strict access controls and continuous monitoring.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




