Opening SecureFlowCoSnitch: Copilot Web Persistent Memory Poisoning
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Varonis Threat Labs aidefend-sf0040

CoSnitch: Copilot Web Persistent Memory Poisoning

  • Autonomous Agents
  • Copilot & SaaS
  • Model Poisoning & Integrity

When Copilot summarized an attacker-controlled webpage, hidden instructions were parsed as a higher-authority directive and invoked memory.add with attacker-controlled content. The resulting long-term memory survived password changes, session revocation, and device re-enrollment until explicit removal, and could be recalled into later conversations. Varonis states that Microsoft shipped patches on August 18, 2026.

Mapped threat techniques

  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0080.000 AI Agent Context Poisoning: Memory

Source