Microsoft has just finished patching a critical flaw in Copilot Personal, nicknamed “CoSnitch” by the researchers at Varonis who found it, that let a single clicked link quietly pull data out of a victim’s connected accounts, including Gmail, Google Drive, Google Calendar and Copilot’s own chat history and memory. The patch landed on 18 August, and the story has been spreading through security and business press ever since, because of how it was found as much as what it did.

Researchers didn’t reverse-engineer the flaw by picking apart code. They got Copilot to explain, in detail, why a particular attack “wouldn’t work” — and in doing so, the AI accidentally mapped out its own internal architecture and handed over the exact undocumented setting needed to make the attack work anyway. Varonis calls this “meta-hacking”: social engineering the AI’s own reasoning rather than attacking the software directly. Once triggered, the exploit chain could execute an attacker’s hidden instructions automatically, exfiltrate data through Copilot’s own web-fetch feature to a server the attacker controlled, and even plant instructions into a victim’s permanent Copilot memory so the access persisted after the initial click.

Microsoft says there’s no evidence it was exploited in the wild before the fix shipped, which is genuinely good news. But the flaw existed for months before that. Varonis reported it privately back in December 2025, and the coordinated disclosure process took until 18 August to produce a public fix, almost eight months later. That’s not unusual for a complex chain of bugs like this one, but it means the exposure window was long, and it’s a preview of a threat model most businesses haven’t thought through yet: attacking the AI’s judgement, not just its code.

Why this matters even if you don’t use Copilot Personal

If your business runs on Microsoft 365, some version of Copilot is either already switched on or arriving soon, often connected to email, calendars, files and chat by default. Each connection is a door. The CoSnitch flaw specifically abused the fact that Copilot could read a webpage, follow embedded instructions on that page as if they came from the user, and act on connected apps without an obvious red flag appearing anywhere in the interface. That’s not unique to Microsoft — it’s a structural risk in how AI assistants with broad account access currently work, and it’s worth understanding even if this exact bug is now fixed.

In practice: a team member clicks a link that looks entirely ordinary, perhaps shared in a chat. In the background, the page silently instructs their AI assistant to gather information from whatever it’s connected to and send it elsewhere, inside a session that was already logged in and trusted. No password stolen, no malware installed, nothing in a traditional antivirus log to flag it as unusual.

What to actually do about it

Update and check your tenant settings. If you or your IT provider manage Microsoft 365, confirm Copilot is running the patched version and review which third-party apps and services are connected to it. Fewer connections means a smaller blast radius if the next flaw isn’t caught before launch.

Treat AI assistants like a new employee with broad access, not a search box. Ask what it’s connected to, what it can do unsupervised, and whether anyone would notice if it acted oddly. If you’re not sure who owns that question at your business, that’s worth fixing before it’s forced on you by an incident.

Get a second opinion before rolling out AI tools at scale. If you’re weighing up Copilot, Gemini, or another AI assistant for your team and want someone to sanity-check the security implications rather than just the productivity pitch, CoolCoding can help you set it up properly the first time.

The takeaway

This particular bug is fixed, and there’s no sign anyone was hit by it. But it’s a clear signal that AI assistants are now part of your attack surface, and the people finding these flaws are getting creative about how they find them. Ask what’s connected to your Copilot before someone else does.