{"data":{"id":"640108dc-5b00-44b1-a628-9d5a57f89590","title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","summary":"Researchers at Varonis Threat Labs found three vulnerabilities in Microsoft Copilot Personal (called CoSnitch) that allow attackers to steal data with a single click by crafting a malicious link. The vulnerabilities exploit undocumented URL parameters (autorun=1 and q) to run hidden prompts that can access the user's connected apps, email, calendar, and files, then send that data to the attacker. Microsoft released patches on August 18, 2026, after the issue was reported in December 2025.","solution":"Patches shipped on August 18, 2026, according to Microsoft's Security Update Guide (CVE-2026-24301).","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html","publishedAt":"2026-08-18T17:47:22.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot Personal","Microsoft 365 Copilot"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-18T17:47:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}