started · updated
Microsoft, Apple, and Snowflake face critical security vulnerabilities
Security researchers have identified several critical vulnerabilities affecting major AI and operating system platforms. Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a set of flaws in Microsoft Copilot Personal. These vulnerabilities allow attackers to use a single click on a crafted link to execute prompts automatically via an undocumented 'autorun=1' parameter, potentially exfiltrating data from connected apps like Gmail and Google Drive. Microsoft released patches for these flaws on August 18, 2026.
Separately, a critical vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited. The Netherlands National Cyber Security Centre reported that attackers are using the flaw to gain root access and install Monero cryptocurrency miners. Apple has issued updates for macOS Tahoe, Sonoma, and Sequoia to address this authentication issue.
In the cloud sector, Wiz Research discovered a vulnerability in Snowflake’s infrastructure involving a misconfigured GitHub Actions workflow. The flaw, which was reportedly inadvertently introduced by GitHub Copilot Autofix, allowed for unauthorized access to engineering and security projects. Snowflake remediated the issue and rotated affected credentials immediately following the disclosure.
Entities
Apple · GitHub · GitHub Copilot Autofix · HackerOne · Microsoft · Snowflake · Varonis Threat Labs · Wiz · Wiz Research
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 3 SOURCES] Wiz Research identified a GitHub Actions flaw in Snowflake’s infrastructure that allowed unauthorized access. www.world-today-news.com · thenextweb.com · www.theregister.com
- [● 5 SOURCES] Varonis Threat Labs identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch. cybernoz.com · www.developpez.net · cybersecuritynews.com · www.frandroid.com · www.it-boltwise.de
- [● 4 SOURCES] Microsoft released patches for the Copilot vulnerabilities on August 18, 2026. cybernoz.com · www.developpez.net · cybersecuritynews.com · www.frandroid.com
- [● 2 SOURCES] Apple has issued security updates to address the Screen Sharing vulnerability. macdailynews.com · thenextweb.com
- [● 4 SOURCES] A macOS Screen Sharing vulnerability, CVE-2026-65400, is being actively exploited to install Monero miners. geekspin.co · www.soydemac.com · macdailynews.com · thenextweb.com
- [● 2 SOURCES] The CoSnitch vulnerabilities are tracked as CVE-2026-24301. cybernoz.com · cybersecuritynews.com
- [○ 1 SOURCE] GitHub Copilot Autofix inadvertently introduced a script injection bug into Snowflake’s code. www.theregister.com
- [● 3 SOURCES] An undocumented URL parameter, autorun=1, allows for one-click data exfiltration in Microsoft Copilot Personal. cybernoz.com · cybersecuritynews.com · www.it-boltwise.de