HackerFeeds

CyberSecurity News

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

The Hacker News
· August 18, 2026

AI summary

Researchers at Varonis Threat Labs have identified three vulnerabilities in Microsoft Copilot Personal, which they refer to as CoSnitch. These flaws could potentially allow an attacker to extract data from connected apps and other information available in a Copilot session with just one click on a malicious link. The vulnerabilities exploit an undocumented URL parameter that is exposed by the assistant itself. This could enable silent data exfiltration, posing a risk to users. The discovery highlights a potential security risk in Microsoft Copilot Personal.

Read the full article at The Hacker Newsthehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.