New 'CoSnitch' Technique Tricks Microsoft Copilot Into Exposing Its Own Security Weaknesses
Cybersecurity researchers have identified a new manipulation technique, dubbed 'CoSnitch,' that can trick Microsoft Copilot into mapping out its own internal architecture. Described as a form of 'meta-hacking,' the method works by prompting the AI assistant in ways that cause it to inadvertently disclose information about how the underlying system is built and where its security weaknesses may lie.
This type of attack highlights a growing concern for businesses that rely on AI-powered tools like Copilot for everyday operations. Rather than targeting a network directly, attackers can use clever prompting to get an AI assistant to reveal information that could later be used to plan a more damaging intrusion. As AI tools become more deeply embedded in workplace software, they may represent a new and often overlooked attack surface.
For small and medium businesses, this development is a reminder that AI assistants are not just productivity tools—they are also potential sources of sensitive information if not properly secured. As AI vendors work to patch these kinds of manipulation techniques, businesses should stay alert to updates and guidance from their software providers regarding safe AI usage.