Signal

'CoSnitch' let a single link silently drain data from Microsoft Copilot's connected accounts — a reminder that AI assistants inherit the trust of everything they're plugged into

Security researchers at Varonis disclosed CoSnitch (CVE-2026-24301), a chained flaw in Microsoft Copilot Personal that let a malicious link trigger a hidden prompt and exfiltrate data from connected accounts like Gmail and Google Drive with no real user interaction — patched by Microsoft on 18 August.