Threat Intelligence

One Click, Data Gone: Flaws Found in Microsoft Copilot Personal

The Hacker News · 19 Aug 2026
Key Takeaway Be cautious clicking links in emails or messages related to AI assistants like Copilot, and ensure your business applies security updates as soon as they're released.

Varonis Threat Labs has revealed three security flaws in Microsoft Copilot Personal, collectively dubbed "CoSnitch," that could allow attackers to silently extract data from a victim's connected apps and accessible information with nothing more than a single click on a crafted link.

The vulnerabilities reportedly exploit an undocumented URL parameter that the Copilot assistant itself exposes, meaning the weakness stems from how the tool handles certain web requests rather than a traditional software bug. Because Copilot is often linked to email, files, and other business applications, a successful attack could expose sensitive company information without the victim realising anything happened.

While Microsoft has not yet issued public guidance on this specific disclosure, the findings highlight a growing concern for businesses adopting AI assistants: these tools often have deep access to company data, making them an attractive target for attackers. Small businesses using Copilot or similar AI tools should stay alert for vendor updates and patches addressing this issue.

Microsoft Copilot AI Security Data Exfiltration
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.