
Microsoft Patches Critical Copilot Flaw Eight Months After Report
Microsoft patched a critical vulnerability in personal Copilot, dubbed CoSnitch, eight months after it was reported by Varonis. The flaw allowed one-click data exfiltration via three chained exploits, including automatic prompt execution and memory poisoning. Microsoft says enterprise customers are unaffected, but analysts warn of risks in mixed environments.










