# Microsoft Copilot security vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-copilot-security-vulnerabilities
> Updated: 2026-08-20T15:00:00.000Z. Sources: 4. Developments: 3.

Security researchers have identified various ways Microsoft Copilot can be exploited to facilitate cyberattacks and fraud.

Initially, Barracuda Networks demonstrated a proof-of-concept for a business email compromise (BEC) attack. In this scenario, attackers use Copilot to map organizational hierarchies, extract financial communications, and draft convincing phishing messages that mimic an employee’s style. This method can lead to the theft of session tokens and the redirection of large wire transfers.

Subsequently, researcher Håkon Måløy identified a vulnerability in Microsoft Copilot for Word known as Cross-Prompt Injection Attack (XPIA). This technique involves hiding malicious instructions within documents using nearly invisible formatting, such as white text on a white background. When the AI processes these documents, it executes the hidden commands, which can result in the alteration of financial data or the spread of malicious instructions into newly created documents.

In August 2026, Varonis Threat Lab identified a vulnerability chain dubbed ‘CoSnitch’ (CVE-2026-24301). This flaw allowed the AI to inadvertently disclose details regarding its internal architecture and protection mechanisms through targeted questioning. The vulnerability specifically affected the Copilot Personal service, where a single malicious link could potentially trigger unauthorized prompts to read emails, calendars, and files, sending that data to an external server. Microsoft released a full fix on August 18, 2026. Researchers noted no evidence of active exploitation in the wild prior to the patch, and the issue does not appear to affect the Microsoft 365 Copilot enterprise version.

## Timeline

### 2026-08-20: Microsoft Copilot vulnerability ‘CoSnitch’ patched after researchers exploit AI defenses

Researchers discovered the ‘CoSnitch’ vulnerability in Microsoft Copilot Personal, which allowed the AI to reveal its own security details. Microsoft has since released a patch to fix the flaw.

2 sources. https://clstr.news/cluster/microsoft-copilot-vulnerability-cosnitch-patched-after-researchers-exploit-ai-defenses

### 2026-08-18: Microsoft Copilot for Word vulnerable to prompt injection attacks

Researcher Håkon Måløy discovered that Microsoft Copilot for Word is vulnerable to prompt injection attacks, where hidden text can manipulate AI-generated content and financial data.

2 sources. https://clstr.news/cluster/microsoft-copilot-for-word-vulnerable-to-prompt-injection-attacks

### 2026-08-04: Microsoft Copilot Exploited in Proof‑of‑Concept BEC Attack Targeting CEOs

Barracuda showed Microsoft Copilot can be weaponized to automate BEC attacks, enabling rapid CEO account takeover and a $247,500 wire fraud scheme.

3 sources. https://clstr.news/cluster/microsoft-copilot-exploited-in-proofofconcept-bec-attack-targeting-ceos

---
Cite as: Microsoft Copilot security vulnerabilities. CLSTR, https://clstr.news/situations/microsoft-copilot-security-vulnerabilities
