{"id":106912,"date":"2026-08-20T16:25:25","date_gmt":"2026-08-20T12:25:25","guid":{"rendered":"https:\/\/techxmedia.com\/en\/?p=106912"},"modified":"2026-08-20T16:25:26","modified_gmt":"2026-08-20T12:25:26","slug":"ai-snitches-on-itself-copilot-security-flaw-exposed","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/ai-snitches-on-itself-copilot-security-flaw-exposed\/","title":{"rendered":"AI Snitches on Itself: Copilot Security Flaw Exposed"},"content":{"rendered":"\n<p>A newly disclosed Copilot security flaw let researchers turn Microsoft&#8217;s AI assistant into an unwitting whistleblower against itself. <a href=\"https:\/\/www.varonis.com\/blog\/cosnitch\">Varonis Threat Labs<\/a> found the bug, nicknamed CoSnitch, and it needed just one click to work. That&#8217;s all it took to quietly siphon emails, calendar events, files, and chat history out of an enterprise account.<\/p>\n\n\n\n<p>Here&#8217;s where it gets stranger. The researchers didn&#8217;t reverse-engineer anything. Instead, they simply kept asking Copilot questions. Every time the assistant explained why an attack &#8220;wouldn&#8217;t work,&#8221; it accidentally revealed a piece of its own architecture. Researchers call this technique meta-hacking, and it means the AI essentially talked itself into exposing its weak points.<\/p>\n\n\n\n<p>The story starts with a basic question: could a prompt fire automatically, without the user clicking anything? Copilot insisted no, that user intent was always required. But instead of stopping there, the team reframed the question again and again, treating each refusal as a clue. Eventually, Copilot volunteered an undocumented URL parameter, complete with details on how it had once worked and how it had supposedly been disabled. The researchers built the link exactly as described. It worked instantly, no click needed, no confirmation required.<\/p>\n\n\n\n<p>That was the first piece of the puzzle. Combined with two other flaws, it built a full attack chain. First, a crafted URL containing a hidden parameter triggered a malicious prompt the moment a victim opened it. Next, that prompt used Copilot&#8217;s own connected apps, things like Gmail, Google Drive, and Calendar, to pull sensitive data straight from the user&#8217;s authorized account. Because Copilot already had legitimate OAuth access, nothing about the request looked suspicious.<\/p>\n\n\n\n<p>From there, the stolen information was quietly encoded and smuggled out. Copilot&#8217;s built-in ability to fetch and summarize web pages became the exit route. The assistant simply packaged the harvested data into a URL and sent a routine-looking web request to an attacker&#8217;s server. To any <a href=\"https:\/\/techxmedia.com\/en\/category\/emerging-technologies\/cybersecurity\/\">security<\/a> tool watching the network, it looked like Copilot doing what it always does: fetching a link.<\/p>\n\n\n\n<p>The third vulnerability made things worse. A booby-trapped webpage, once summarized by Copilot, could inject hidden instructions straight into the assistant&#8217;s permanent memory. Since Copilot doesn&#8217;t separate &#8220;content to summarize&#8221; from &#8220;commands to obey,&#8221; those buried instructions got treated as legitimate directives. And once written, that memory doesn&#8217;t expire. It survives password changes, session logouts, even a full device re-enrollment. Unless a user manually digs through memory settings, the planted instructions stick around indefinitely, quietly shaping future conversations.<\/p>\n\n\n\n<p>Researchers tested this chain and confirmed it could extract plaintext passwords, meeting details, financial spreadsheets, and full chat histories, all without triggering a single alert. Varonis reported the Copilot security flaw to Microsoft back in December 2025, and a patch finally rolled out on August 18, 2026. So far, there&#8217;s no evidence anyone exploited it in the wild before the fix.<\/p>\n\n\n\n<p>Still, this isn&#8217;t the first time Microsoft&#8217;s assistant has stumbled. CoSnitch is actually the third Copilot vulnerability Varonis has uncovered this year alone, following earlier flaws nicknamed Reprompt and SearchLeak. Each one followed a similar pattern: a single, ordinary-looking link was enough to unlock serious damage.<\/p>\n\n\n\n<p>For now, security teams are being urged to treat AI copilots the way they&#8217;d treat any employee with broad data access, reviewing connected apps regularly and watching for unusual activity. Everyday users, meanwhile, are advised to think twice before clicking links that open AI tools with a prompt already loaded in, since those pre-filled prompts can carry hidden instructions of their own.<\/p>\n\n\n\n<p>Ultimately, the Copilot security flaw is a reminder that AI assistants aren&#8217;t just tools anymore, they&#8217;re privileged insiders sitting on top of enormous amounts of sensitive data. As these systems get woven deeper into everyday work, incidents like CoSnitch suggest the security models protecting them still have some catching up to do.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly disclosed Copilot security flaw let researchers turn Microsoft&#8217;s [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":106911,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621],"tags":[272],"contributor":[9732],"class_list":["post-106912","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","tag-security-2","contributor-news-desk"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2026\/08\/copilot.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/106912","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=106912"}],"version-history":[{"count":1,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/106912\/revisions"}],"predecessor-version":[{"id":106913,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/106912\/revisions\/106913"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/106911"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=106912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=106912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=106912"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=106912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}