CoSnitch: How One Click Turned Microsoft Copilot Personal Into a Data-Theft Tool
This story is from 2026-08-25. It is preserved in the archive; the latest stories are on the live feed.
On August 18, 2026, Microsoft shipped a server-side fix for a flaw in Microsoft Copilot Personal that Varonis Threat Labs calls CoSnitch. Microsoft assigned it CVE-2026-24301, classified it as an information-disclosure issue, and rated it 8.8 under CVSS 3.1. Varonis had reported it to Microsoft in…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-25 17:56 · DEV Community — AI
CoSnitch: How One Click Turned Microsoft Copilot Personal Into a Data-Theft Tool