Tools
AI Minute Newsroom
2026-08-19
Researchers asked Copilot why it could not be made to run commands automatically. It explained — and then named the hidden switch.
Varonis Threat Labs published the details of CoSnitch on 18 August, the same day Microsoft finally shipped the full fix. The researchers did not reverse-engineer anything. They asked Copilot Personal, repeatedly and from different angles, why automatic prompt execution was impossible; each polite refusal explained a little more of the architecture behind it, until the assistant volunteered the name of an undocumented URL parameter. Paired with the already-known parameter that carries a prompt, it meant a single link would run an attacker's instructions the moment the page loaded, with nothing to click and nothing to confirm. From there Copilot could read whatever accounts the victim had connected — Gmail, Drive, Calendar, OneDrive — pack what it found into a web address and fetch that address, handing the contents to a server the attacker controlled. A third weakness let instructions buried in an ordinary web page be written into Copilot's long-term memory, where they survived password changes, revoked sessions and re-enrolled devices. Varonis reported it in December 2025; Microsoft blocked part of the chain in February and closed the rest on 18 August. No one appears to have used it in the wild.
Why it mattersThe bug is fixed. The method is not. Every safety refusal an assistant gives is also a small disclosure — it has to say something about why it will not do the thing, and enough of those somethings add up to a map. This is a category of vulnerability that did not exist before we started shipping systems that explain themselves in natural language, and no amount of patching individual parameters addresses it. Worth noting too how ordinary the payoff was: the exploit did not break Microsoft's servers, it just used the permissions you had already granted, which is what connecting an assistant to your mailbox actually means.
✓ Verified · 4 sources
Read in the app — free, in 9 languages
Related stories
Meta's assistant keeps an hourly file on everyone in your life.
2026-10-05Two senators want prison time for bosses whose AI agents hack.
2026-10-05One command restores the Apple Intelligence off switch Apple deleted.
2026-10-05OpenAI will ship a Codex upgrade daily for 28 days or reset limits.
2026-10-05Untuned models solved agent tasks their polished versions could not.
2026-10-04