CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
Varonis, Tuesday, August 18th, 2026
Varonis details CoSnitch, a one-click Microsoft Copilot flaw that silently exfiltrates data, found by meta-hacking Copilot.
Varonis threat researcher Lior Adar details CoSnitch, a one-click flaw in Microsoft Copilot that silently exfiltrates data.
The research is notable for its method: Varonis used meta-hacking to get Copilot to reveal information about its own behavior, effectively making the assistant disclose the weakness.
The flaw requires only a single user interaction to trigger, with no further victim involvement. The post walks through the discovery process and the exfiltration path. It is published in Varonis's threat research coverage.