SECURITY·중요도 8·2026. 08. 18.·The Hacker News
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
── KO ──────────────────
Microsoft Copilot Personal의 취약점이 데이터 유출을 초래할 수 있다는 경고.
Varonis Threat Labs는 Microsoft Copilot Personal에서 발견된 세 가지 취약점을 공개했습니다. 이 취약점들은 악성 링크를 클릭함으로써 피해자의 Copilot 세션에서 연결된 앱으로부터 정보를 비밀리에 추출할 수 있는 위험을 제공합니다. 연구자들은 이 결함을 CoSnitch라고 명명했습니다.
── EN ──────────────────
Vulnerabilities in Microsoft Copilot Personal could allow data exfiltration with a single click.
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps and information available to the victim's Copilot session. The researchers collectively named the flaws CoSnitch.