Copilot tricked into revealing a one-click data theft flaw
Microsoft Copilot Personal exposed an undocumented URL mechanism that researchers used to run attacker-supplied prompts without user confirmation. The CoSnitch attack could turn a single phishing link, QR code, or message into a way to search connected mail a…
Copilot disclosed its own attack path Varonis Threat Labs discovered the issue through meta-hacking, repeatedly asking Copilot why an attempted attack would fail. In answering, the assistant reveale… [+1560 chars]