View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

CoSnitch flaws let one click hijack Microsoft Copilot Personal

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • CoSnitch flaws let one click hijack Microsoft Copilot Personal
    Researchers disclosed CoSnitch flaws in Microsoft Copilot Personal.
    • Microsoft Copilot Personal at copilot.microsoft.com was affected; Microsoft 365 Copilot was not identified as affected.
    • CVE-2026-24301 enabled access to connected Gmail, Google Drive, Google Calendar, chat history, and Copilot memory.
    • A crafted link paired the q= and undocumented autorun=1 parameters to execute prompts in an authenticated session without user interaction.
    • Prompts could exfiltrate data to attacker-controlled servers, including https://webhook.site/75aabb18-9bcf-4383-9e29-349fbc4c40e8/SUPPORT.
    • A separate web-summarization prompt-injection path could persist attacker instructions in Copilot memory.
      πŸ“„ Source: msrc.microsoft.com Β· πŸ“Ž Coverage: arstechnica.com Β· πŸ‘ via Dark Reading

πŸ“‹ ADVISORIES

  • AWS details custom authentication for AgentCore Gateway tool integrations
    AWS describes using a request Lambda interceptor to add custom authentication to AgentCore Gateway.
    • Amazon Bedrock AgentCore Gateway customers integrating AI agents with tools
    • AgentCore Gateway natively supports OAuth 2.0, IAM, and API key authentication
    • Legacy HTTP Basic Authentication environments require custom authentication handling
    • A request Lambda interceptor extends the gateway’s authentication flow for tool requests
      πŸ“Ž Coverage: aws.amazon.com Β· πŸ‘ via AWS Security Blog

πŸ”“ CVEs & KEV

  • Other: 19 CVEs (worst 9.9)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check