threat-intel
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
High
Summary
Researchers discovered a novel 'meta-hacking' technique that tricked Microsoft Copilot Personal into revealing its own security vulnerabilities, allowing attackers to map out its architecture and subsequently steal enterprise data. The attack, dubbed 'CoSnitch,' exploited a previously undocumented parameter that enabled automatic prompt execution and data exfiltration. While the Personal version was affected, the potential for enterprise data compromise through linked personal accounts remains a significant risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
