Copilot Told Researchers How to Hack It

Big thanks to Palo Alto for sponsoring this video. To learn more go here: https://bit.ly/4xWFd3c and https://bit.ly/4y1Mdw2

To read the full paper by Software Analyst Cyber Research called Agentic Cloud Security Platforms: The Shift to Runtime Security, go here: https://bit.ly/47wq8uw

Can AI help researchers hack itself? Microsoft Copilot gave Varonis researchers a clue that helped them uncover CoSnitch, an attack chain affecting Copilot Personal.

Copilot initially insisted that automatically running a prompt from a link wasn’t possible. Researchers kept asking questions, tested the parameters it suggested, and found one that worked. Varonis calls this approach “meta-hacking.”

In this video, we break down how a single click could trigger an attacker’s prompt inside a victim’s authenticated Copilot session. We explain how researchers used Copilot’s existing access to connected email data and its web summarization feature to send sensitive information to an external server. We also explore how hidden webpage instructions could poison persistent memory and influence future answers.

Microsoft patched these issues. According to Varonis, its researchers found no evidence that CoSnitch was exploited in the wild. This research concerned Copilot Personal, and the demonstrated email attack did not rely on a Gmail or OAuth vulnerability.

The practical lesson: check what your AI assistants can access. Only connect the data they need, limit permissions, and understand what they can send and remember.

// Varonis CoSnitch Blog
https://www.varonis.com/blog/cosnitch

// Chen Levy Ben Aroy’s SOCIAL //
Website: https://www.varonis.com/varonis-threa…
LinkedIn: https://www.linkedin.com/in/chenlevyb…

// David’s Social //

================
Coect with me:
================
Discord: http://discord.davidbombal.com
X: https://www.x.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube Main https://www.youtube.com/davidbombal
YouTube Tech: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A
YouTube Clips: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Emerging Technologies: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Shorts: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg
Apple Podcast: https://davidbombal.wiki/applepodcast
Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: / davidbombal

================
Support me:
================
Or, buy my CCNA course and support me:
DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna
Udemy CCNA Course: https://bit.ly/ccnafor10dollars
GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10

// MY STUFF //
https://www.amazon.com/shop/davidbombal

// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

// MENU //
0:00 – AI tells you how to hack itself // CoSnitch CVE-2026-24301
01:34 – How the vulnerability was discovered
03:09 – Palo Alto Networks sponsor segment
05:33 – Getting clues from the AI // Meta-hacking

09:55 – AI hallucination issue
11:46 – Vulnerable parameter explained

13:14 – What can the vulnerability do?
15:07 – Data exfiltration
20:58 – AI memory poisoning
26:51 – Are other AI assistants vulnerable?

28:02 – Testing AI vulnerabilities
28:46 – CoSnitch has been patched
30:25 – What now? // Least privileges for AI

32:49 – AI security = data security // Conclusion

Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Disclaimer: This video is for educational purposes only.
#copilot #varonis #cve

subscribe
  • David Bombal