< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 4 sources · 16 days · First seen · Last updated

Microsoft Copilot security vulnerabilities

Overview

Security researchers have identified various ways Microsoft Copilot can be exploited to facilitate cyberattacks and fraud.

Initially, Barracuda Networks demonstrated a proof-of-concept for a business email compromise (BEC) attack. In this scenario, attackers use Copilot to map organizational hierarchies, extract financial communications, and draft convincing phishing messages that mimic an employee’s style. This method can lead to the theft of session tokens and the redirection of large wire transfers.

Subsequently, researcher Håkon Måløy identified a vulnerability in Microsoft Copilot for Word known as Cross-Prompt Injection Attack (XPIA). This technique involves hiding malicious instructions within documents using nearly invisible formatting, such as white text on a white background. When the AI processes these documents, it executes the hidden commands, which can result in the alteration of financial data or the spread of malicious instructions into newly created documents.

In August 2026, Varonis Threat Lab identified a vulnerability chain dubbed ‘CoSnitch’ (CVE-2026-24301). This flaw allowed the AI to inadvertently disclose details regarding its internal architecture and protection mechanisms through targeted questioning. The vulnerability specifically affected the Copilot Personal service, where a single malicious link could potentially trigger unauthorized prompts to read emails, calendars, and files, sending that data to an external server. Microsoft released a full fix on August 18, 2026. Researchers noted no evidence of active exploitation in the wild prior to the patch, and the issue does not appear to affect the Microsoft 365 Copilot enterprise version.

Entities

Copilot · Microsoft · Google · OpenAI · Varonis

Timeline

  1. 22 days ago

    [TECHNOLOGY] 2 sources
    Microsoft Copilot vulnerability ‘CoSnitch’ patched after researchers exploit AI defenses

    Researchers discovered the ‘CoSnitch’ vulnerability in Microsoft Copilot Personal, which allowed the AI to reveal its own security details. Microsoft has since released a patch to fix the flaw.

  2. 25 days ago

    [TECHNOLOGY] 2 sources
    Microsoft Copilot for Word vulnerable to prompt injection attacks

    Researcher Håkon Måløy discovered that Microsoft Copilot for Word is vulnerable to prompt injection attacks, where hidden text can manipulate AI-generated content and financial data.

  3. about 1 month ago

    [TECHNOLOGY] 3 sources
    Microsoft Copilot Exploited in Proof‑of‑Concept BEC Attack Targeting CEOs

    Barracuda showed Microsoft Copilot can be weaponized to automate BEC attacks, enabling rapid CEO account takeover and a $247,500 wire fraud scheme.

Sources

instalki.pl · logicno.com · telefonino.net · tomshw.it

This summary has been updated 1 time: see revision history