AINewsnow

CoSnitch: How One Click Turned Microsoft Copilot Personal Into a Data-Theft Tool

This story is from 2026-08-25. It is preserved in the archive; the latest stories are on the live feed.

On August 18, 2026, Microsoft shipped a server-side fix for a flaw in Microsoft Copilot Personal that Varonis Threat Labs calls CoSnitch. Microsoft assigned it CVE-2026-24301, classified it as an information-disclosure issue, and rated it 8.8 under CVSS 3.1. Varonis had reported it to Microsoft in…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-08-25 17:56 · DEV Community — AI
    CoSnitch: How One Click Turned Microsoft Copilot Personal Into a Data-Theft Tool

More stories

  1. Microsoft exec called AI scraping the “largest theft of labor in human history” — Ars Technica AI
  2. OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web — The Verge AI
  3. Implementing defense-in-depth authorization for MCP tools on Amazon Quick — AWS Machine Learning Blog
  4. OpenAI's latest AI revelation is a 'serious situation,' Microsoft's Suleyman tells CNBC — CNBC Technology
  5. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  6. Uncontrolled AI could lead to 'silicon species' rivalling humans, warns Microsoft — BBC Technology
  7. Deployed Qwen 3.6 35B A3B on a single DGX Spark supporting 12 concurrent users at 262K context. Are there better ways to optimize this? — r/LocalLLM
  8. Sources: the USPTO and US Copyright Office were surprised by the DOJ's brief supporting OpenAI and Microsoft in their dispute with the New York Times (Axios) — Techmeme

Get the daily brief of stories like this at 6:30 every morning →