Opening SecureFlowCoSnitch: Copilot Web Autorun Data Exfiltration
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Varonis Threat Labs aidefend-sf0039

CoSnitch: Copilot Web Autorun Data Exfiltration

  • Autonomous Agents
  • Copilot & SaaS
  • Data Exfiltration

A crafted copilot.microsoft.com link combined attacker instructions in q with the undocumented autorun=1 parameter. In an authenticated browser session, Copilot submitted the prompt without a separate confirmation, retrieved data from connected services or prior conversations, encoded selected values into an attacker URL, and fetched it. Microsoft shipped patches on August 18, 2026.

Mapped threat techniques

  • AML.T0051.000 LLM Prompt Injection: Direct
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0025 Exfiltration via Cyber Means

Source