vulnerability Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps Varonis Threat Labs discovered three vulnerabilities, collectively named ‘CoSnitch,’ in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps. The flaws enable an attacker to inject commands and steal sensitive information like email content, calend… The Hacker News · Aug 18, 2026 High CVE-2026-24301CVE-2026-24299prompt injectiondata exfiltrationmemory poisoning