π΅οΈ RESEARCH & DEEP DIVES
- CoSnitch flaws let one click hijack Microsoft Copilot Personal
Researchers disclosed CoSnitch flaws in Microsoft Copilot Personal.- Microsoft Copilot Personal at copilot.microsoft.com was affected; Microsoft 365 Copilot was not identified as affected.
- CVE-2026-24301 enabled access to connected Gmail, Google Drive, Google Calendar, chat history, and Copilot memory.
- A crafted link paired the q= and undocumented autorun=1 parameters to execute prompts in an authenticated session without user interaction.
- Prompts could exfiltrate data to attacker-controlled servers, including https://webhook.site/75aabb18-9bcf-4383-9e29-349fbc4c40e8/SUPPORT.
- A separate web-summarization prompt-injection path could persist attacker instructions in Copilot memory.
π Source: msrc.microsoft.com Β· π Coverage: arstechnica.com Β· π via Dark Reading
π ADVISORIES
- AWS details custom authentication for AgentCore Gateway tool integrations
AWS describes using a request Lambda interceptor to add custom authentication to AgentCore Gateway.- Amazon Bedrock AgentCore Gateway customers integrating AI agents with tools
- AgentCore Gateway natively supports OAuth 2.0, IAM, and API key authentication
- Legacy HTTP Basic Authentication environments require custom authentication handling
- A request Lambda interceptor extends the gatewayβs authentication flow for tool requests
π Coverage: aws.amazon.com Β· π via AWS Security Blog
π CVEs & KEV
- Other: 19 CVEs (worst 9.9)