Microsoft Copilot Personal Flaws Enable One-Click Data Exfiltration via CoSnitch
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could allow a single click on a…
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could allow a single click on a…
CVE-2026-24299 is associated with research by Johann Rehberger on memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot, as…
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
A new attack named MemGhost demonstrates how a single email can inject persistent false memories into AI personal assistants, manipulating their future…
Microsoft has issued a warning about a new attack vector targeting AI agents that use the Model Context Protocol (MCP). Attackers can…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed SearchLeak, could have allowed attackers to exfiltrate emails, files, and MFA codes…
A critical command injection vulnerability in Microsoft 365 Copilot Enterprise Search, discovered by Varonis Threat Labs, allows one-click data exfiltration. Microsoft assigned…
EchoLeak is a prompt injection vulnerability in Microsoft 365 Copilot disclosed by Aim Security in June 2025. An attacker could craft an…
Microsoft 365 Copilot is the enterprise version of Microsoft's AI assistant. While not affected by CoSnitch, it has been subject to memory…