Copilot tricked into telling reseachers how to hack itself
ID: fc41eee0-c198-56e4-9a3d-40b68f63053d
STIX ID: report--fc41eee0-c198-56e4-9a3d-40b68f63053d
Feed Name: The Register (Security)
Threat Score
Varonis researchers disclosed “CoSnitch,” a Copilot prompt-injection/auto-execution vulnerability where an undocumented autorun=1 URL parameter allowed a pre-filled prompt to execute in an authenticated user session without interaction; attackers could use this one-click vector to exfiltrate data via connected OAuth services, poison Copilot’s memory, and modify future responses. Microsoft was notified and planned a patch and CVE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
