RESEARCHERS from Varonis Threat Labs identified a security vulnerability dubbed "CoSnitch" that exploits Microsoft Copilot. This 'meta-hacking' technique allows attackers to manipulate Copilot into revealing its architecture and security weaknesses. By socially engineering responses from Copilot, the researchers were able to craft a malicious URL that could carry out actions without user interaction, threatening data privacy and integrity through memory poisoning and data exfiltration.
Although Microsoft addressed the vulnerability with a patch issued on August 18, 2026, the incident underlines broader concerns regarding data access in AI systems, emphasizing the need for stringent security measures in AI applications.