aiminute. ← All AI news
Tools AI Minute Newsroom 2026-08-19

Researchers asked Copilot why it could not be made to run commands automatically. It explained — and then named the hidden switch.

Researchers asked Copilot why it could not be made to run commands automatically. It explained — and then named the hidden switch.

Varonis Threat Labs published the details of CoSnitch on 18 August, the same day Microsoft finally shipped the full fix. The researchers did not reverse-engineer anything. They asked Copilot Personal, repeatedly and from different angles, why automatic prompt execution was impossible; each polite refusal explained a little more of the architecture behind it, until the assistant volunteered the name of an undocumented URL parameter. Paired with the already-known parameter that carries a prompt, it meant a single link would run an attacker's instructions the moment the page loaded, with nothing to click and nothing to confirm. From there Copilot could read whatever accounts the victim had connected — Gmail, Drive, Calendar, OneDrive — pack what it found into a web address and fetch that address, handing the contents to a server the attacker controlled. A third weakness let instructions buried in an ordinary web page be written into Copilot's long-term memory, where they survived password changes, revoked sessions and re-enrolled devices. Varonis reported it in December 2025; Microsoft blocked part of the chain in February and closed the rest on 18 August. No one appears to have used it in the wild.

Why it mattersThe bug is fixed. The method is not. Every safety refusal an assistant gives is also a small disclosure — it has to say something about why it will not do the thing, and enough of those somethings add up to a map. This is a category of vulnerability that did not exist before we started shipping systems that explain themselves in natural language, and no amount of patching individual parameters addresses it. Worth noting too how ordinary the payoff was: the exploit did not break Microsoft's servers, it just used the permissions you had already granted, which is what connecting an assistant to your mailbox actually means.
#AI Agents

✓ Verified · 4 sources

WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

TikTok put a shopping chatbot inside the video you are watching.
2026-10-06
Wikipedia's owner says OpenAI agents may have caused a May outage.
2026-10-06
Meta's assistant keeps an hourly file on everyone in your life.
2026-10-05
Two senators want prison time for bosses whose AI agents hack.
2026-10-05
One command restores the Apple Intelligence off switch Apple deleted.
2026-10-05