Wednesday, 19 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Experts manage to hack Microsoft Copilot by continually asking it questions about itself

TechRadar ·
Experts manage to hack Microsoft Copilot by continually asking it questions about itself

Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data Exploit used malicious URLs and persistent memory poisoning to bypass guardrails Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked.

It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.

Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named CoSnitch .

The name is a major hint at what the vulnerability is - as CoSnitch is a chain of three vulnerabilities which Microsoft later labeled as CVE-2026-24301, giving it a severity score of 8.8/10 (high), and fixing it with a patch.

You can’t trick me, and I’ll tell you exactly why Cybercriminals have long been using AI as part of their arsenal, as it helps them draft convincing phishing emails, write malicious code, and identify high-value targets - and developers have responded by placing guardrails, which making AI outright refuse to do certain things.

In the report, Varonis said its researchers did not hunt for bugs in the code or try to reverse-engineer an existing exploit.

They just talked to the AI , and with each subsequent question, learned more about its guardrails and how they work.

They called the technique “meta-hacking”.

Whenever Copilot declined a request, it explained why, giving the researchers snippets of insight into how it operates.

Or, as Varonis hinted, it “snitched” on itself.

This, eventually, helped them map out its defenses and learn how to work around it: “The resistance is part of the technique,” they explained.

“Each “that won’t work because…” is an invitation to probe the “because.” You don’t exploit the model.

You manipulate it into cooperating.” After a long conversation with Copilot, the researchers were told, inadvertently, how to create a URL which would, as soon as it was clicked, kick off a chain reaction that resulted in sensitive data exfiltration.

The dangers of connecting AI to apps So, Varonis learned that by creating a URL like this one - “https://copilot.microsoft.com/?q=&autorun=1*” - they could get Copilot to run any malicious prompt as soon as it was clicked.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›