TGViewer
Linux Linux @sysadminoff · 2.13K subscribers
Post #19451 65
Copilot tricked into revealing a one-click data theft flaw

Microsoft Copilot Personal exposed an undocumented URL mechanism that researchers used to run attacker-supplied prompts without user confirmation. The CoSnitch attack could turn a single phishing link, QR code, or message into a way to search connected mail and files, exfiltrate sensitive data, and alter Copilot’s stored memory.
Source

👉@sysadminoff

https://4sysops.com/archives/copilot-tricked-into-revealing-a-one-click-data-theft-flaw/
More from @sysadminoff
  1. Oct 7, 2026Modern GNOME Weather extensions I updated by list of the best Linux weather apps recently,…
  2. Oct 7, 2026📰 aerynOS Adds Budgie 10.10.3 for Testing, Updates COSMIC to 1.9 The aerynOS October upda…
  3. Oct 7, 2026📰 YSERVER 1.7 Rust X11 Server Narrows Memory Usage Difference With X.Org Server YSERVER c…
  4. Oct 7, 2026📰 The Fanatical Build Your Own Retro Revival Bundle has plenty of great picks Fanatical h…
  5. Oct 7, 2026OpenAI says Codex and ChatGPT Work have reached 40 million active users OpenAI says Codex…
  6. Oct 7, 2026📰 Intel Compiler Engineer Shares Latest Project Gains For APX Last week at the GNU Tools…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →