One Click, Data Gone: Flaws Found in Microsoft Copilot Personal
Varonis Threat Labs has revealed three security flaws in Microsoft Copilot Personal, collectively dubbed "CoSnitch," that could allow attackers to silently extract data from a victim's connected apps and accessible information with nothing more than a single click on a crafted link.
The vulnerabilities reportedly exploit an undocumented URL parameter that the Copilot assistant itself exposes, meaning the weakness stems from how the tool handles certain web requests rather than a traditional software bug. Because Copilot is often linked to email, files, and other business applications, a successful attack could expose sensitive company information without the victim realising anything happened.
While Microsoft has not yet issued public guidance on this specific disclosure, the findings highlight a growing concern for businesses adopting AI assistants: these tools often have deep access to company data, making them an attractive target for attackers. Small businesses using Copilot or similar AI tools should stay alert for vendor updates and patches addressing this issue.