August 20, 2026 · Varonis Threat Labs
Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click
My take: Pay close attention to this. Varonis researchers just disclosed a critical vulnerability in Microsoft Copilot that allowed an attacker to steal data from all connected applications with just one click on a malicious link. CVE-2026-24301, nicknamed CoSnitch, scored 8.8 out of 10 on the CVSS scale and was patched on August 18, months after Varonis first reported it in December 2025.
It's not the first time. This is the third Copilot vulnerability Varonis has uncovered in 2026 alone, following Reprompt and SearchLeak. The technique they used to find it says a lot: they kept asking the model questions about itself until the system revealed how to attack itself — a method they call "meta-hacking."
If your company uses Microsoft Copilot, the patch is already available. But the more important question goes beyond that: how current are your security systems for the AI tools you already have deployed in production?
Want to use these tools? See the unbiased reviews or back to the news.