Last week, a security firm called Varonis dropped a disclosure they named CoSnitch. The target was Microsoft Copilot Personal. The attack was a single crafted URL that, if one of your employees clicked it, would silently drain everything from their connected Gmail, Google Drive, and Google Calendar — no popup, no warning, no second click required.
Microsoft patched it on August 18. But the patch isn't really the story. The story is the pattern it exposes — one that's going to repeat, because the underlying problem isn't fixed yet.
What CoSnitch actually did
Microsoft Copilot Personal is the consumer-facing version of Copilot, available at copilot.microsoft.com and baked into Windows. A big part of its appeal is that it connects to your external accounts via OAuth — you link up your Gmail, your Google Drive, your Google Calendar, and suddenly Copilot can help you search across all of it.
Varonis found three separate weaknesses in that system that could be chained together. The result was CVE-2026-24301: a crafted URL with an undocumented autorun=1 parameter that would execute an embedded prompt silently, without any user confirmation beyond the initial click. One well-crafted link, sent in an email or a Slack message, and Copilot would quietly pull data from every connected OAuth account and ship it out.
No loading spinner. No "Copilot is reading your email." Nothing. Just your data leaving.
Varonis disclosed this to Microsoft in December 2025. Microsoft says it found no evidence of active exploitation before the patch. That's good. But eight months of sitting on that vulnerability — in a tool millions of small businesses use daily — is not exactly a comfort.
The meta-hacking part is the part that should keep you up at night
Here's what's genuinely unsettling about how Varonis found this: they didn't find it by reading source code or fuzzing the API. They found it by interrogating Copilot itself.
The researchers kept asking Copilot why automatic prompt execution was impossible. They reframed the refusals as follow-up questions. They pushed until Copilot, in explaining why something couldn't happen, revealed the mechanisms that made it happen. They called it meta-hacking — social engineering the AI's reasoning until it describes its own architecture well enough to attack it.
That technique is not going away. And it doesn't require a team of researchers. It requires patience and a clever framing. AI tools built to be helpful and explanatory are structurally inclined to reveal more than they should when pushed the right way. Every time a new AI assistant ships with "connect your accounts" and "ask me anything" baked in, the attack surface includes the AI's own willingness to explain itself.
Why small orgs are specifically at risk here
Enterprise security teams have dedicated people auditing OAuth integrations. You probably don't.
A lot of small organizations — NGOs, 15-person marketing firms, municipal departments — run hybrid environments. Google Workspace for email and docs, Microsoft 365 for some Office tools, and a few AI tools connected across both. When you plug all of that into a single AI assistant via OAuth, that assistant becomes the single highest-value target in your environment. Compromising Copilot Personal means compromising everything it has read access to.
And small orgs are not great at auditing this. Most teams connect their apps when an AI assistant asks them to, get some value out of it, and never think again about what permissions they granted. Those OAuth tokens sit there indefinitely. If the AI tool gets compromised, or has a vulnerability, everything connected to it is in play.
The attacker's job got easier because your AI got smarter.
What to do right now
This specific vulnerability is patched. But the hygiene issues that made it dangerous are not.
Update Copilot Personal. If you or anyone on your team uses Microsoft Copilot Personal, make sure the August 18 patch has been applied. On Windows, check Windows Update. On the web, copilot.microsoft.com should have pulled the fix server-side already — but verify.
Audit your connected accounts. Go into your Copilot settings (and any other AI tool you're using — ChatGPT, Gemini, Notion AI, whatever) and look at what OAuth accounts are connected. Be specific. Ask yourself: does this AI actually use this connection in ways that make my life better? If the answer is no, revoke it. Every connected account is blast radius.
Apply this principle everywhere. This isn't just a Copilot problem. Any AI tool that connects to your email, your calendar, your file storage, your CRM — that tool is now a privileged access point into your business. The permissions you grant those tools should get the same scrutiny you'd give a contractor who has a key to your office.
Talk to your team about AI links. Phishing evolved. People know not to click suspicious email attachments. They're not yet trained to think of a crafted Copilot URL as a threat vector. Brief your team: links that trigger AI actions can be weaponized the same way links that trigger downloads can be.
The bigger picture
CoSnitch is a preview. We're in the middle of a wave of AI tools gaining OAuth access to organizational data, and the security ecosystem hasn't caught up. Most of the small organizations we work with have at least three AI tools connected to Google Workspace or Microsoft 365 — often more — and none of them have done a formal permissions audit.
That's not paranoia talking. That's just math. More connected accounts, more potential blast radius, more tools that an attacker might find a clever way to invoke.
The window where "we'll deal with AI security later" is a reasonable answer is closing. CoSnitch showed us one way this can go wrong. There are others being discovered right now.
At CivSafe, auditing AI tool permissions and OAuth sprawl is part of every engagement we run with organizations that have started deploying AI across their teams. If you're not sure what you've connected or what access those tools have, that's worth a conversation.