SECURITY·중요도 8·2026. 08. 18.·The Hacker News

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

── KO ──────────────────

Microsoft Copilot Personal의 취약점이 데이터 유출을 초래할 수 있다는 경고.

Varonis Threat Labs는 Microsoft Copilot Personal에서 발견된 세 가지 취약점을 공개했습니다. 이 취약점들은 악성 링크를 클릭함으로써 피해자의 Copilot 세션에서 연결된 앱으로부터 정보를 비밀리에 추출할 수 있는 위험을 제공합니다. 연구자들은 이 결함을 CoSnitch라고 명명했습니다.


── EN ──────────────────

Vulnerabilities in Microsoft Copilot Personal could allow data exfiltration with a single click.

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps and information available to the victim's Copilot session. The researchers collectively named the flaws CoSnitch.

원문 보기 →목록으로