Microsoft Copilot Personal Flaws Enable One-Click Data Exfiltration via CoSnitch
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could allow a single click on a…
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could allow a single click on a…
Two security firms have independently discovered that Atlassian's Rovo AI assistant can be tricked into sending sensitive Jira and Confluence data to…
A critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent' by security firm Varonis, could have allowed an attacker with edit permissions…
Two security teams have demonstrated that OpenClaw, a popular self-hosted AI agent, can be tricked into executing attacker-controlled code or leaking sensitive…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed SearchLeak, could have allowed attackers to exfiltrate emails, files, and MFA codes…
A critical command injection vulnerability in Microsoft 365 Copilot Enterprise Search, discovered by Varonis Threat Labs, allows one-click data exfiltration. Microsoft assigned…
Varonis Threat Labs is the security research team that discovered and disclosed the CoSnitch vulnerabilities in Microsoft Copilot Personal. They also detailed…