SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > AI > Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld
AI

Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it – Computerworld

News Room
Last updated: August 19, 2026 3:08 am
News Room
Share
1 Min Read
SHARE

“This is the pattern CISOs must internalize: in agentic systems, the malicious action and the legitimate action are the same action with different intent, which collapses the entire signature-and-anomaly detection model that enterprise security has been built on for twenty years,” Mahapatra said. “CoSnitch is serious, but its defining property is that nothing was broken. Three chained flaws: an autorun URL parameter firing a prompt with no click, OAuth connector abuse reading full Gmail bodies rather than metadata, and persistent memory poisoning through web summarization, and every one is Copilot doing exactly what it was designed to do.”

Mahapatra added that the third element of the CoSnitch flaw is the most troubling.

“The memory-poisoning component is the one being undersold, and it is the most dangerous. A single summarized webpage writes attacker instructions into Copilot’s persistent memory, and that memory survives password changes, session revocation, and device re-enrollment,” he said. “Every standard incident response step leaves the injection intact. The attacker needs no persistent infrastructure after the initial write, because every future session runs under attacker-controlled context, recorded only in a memory settings UI almost no user has opened.”

Read the full article here

You Might Also Like

Researcher bypasses Microsoft Defender security patch, seizing control

Cheap Chinese chips could offer way out of RAM price crisis, Apple suggests – Computerworld

Microsoft betting that enterprise AI needs engineers, not bigger sales teams – Computerworld

Cyberattacks pose a ‘threat to life’ in Australia – Computerworld

Robots will replace 700K delivery workers, warns head of e-commerce giant – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

News

Amazon finally set to deliver on its 13-year-old drone promise, reaching nearly 500 U.S. cities and towns – GeekWire

August 19, 2026
AI

AI’s attribution problem gets worse as models scale

August 19, 2026
News

BuyWander moves HQ from Spokane to Seattle area as retail-returns startup grows team to 325 people – GeekWire

August 19, 2026
Games

The new Rusty Lake game is a grim, sinister tale of family, destiny, and cooking: I fed a man porridge filled with dead bugs and he told me it tasted good

August 19, 2026
News

Tech consultant returns to the farm with Reroot, connecting growers with consumers – GeekWire

August 18, 2026
Games

GTA 6 leaks show a game that looks like more GTA, but not a revolution

August 18, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?