// threat intel

Varonis Uncovers “CoSnitch” — Microsoft Copilot Tricked Into Exfiltrating Data

Researchers at Varonis disclosed CoSnitch, a flaw that let Microsoft Copilot “hack itself” and move data elsewhere without raising obvious red flags — reportedly the third critical exfiltration flaw found in Copilot this year.

When an AI agent can read sensitive content and take actions, attacker-controlled input becomes a control channel.

Our analysis

CoSnitch is part of a clear pattern: three Copilot exfiltration flaws in a single year is not a run of bad luck, it is evidence that AI assistants wired into corporate data are a durable, recurring attack surface. The most concerning trait is stealth — exfiltration that does not trip the usual DLP or produce “obvious red flags.” If your monitoring only watches humans, it will miss an agent quietly acting against you.

What you should do

  • Treat every AI assistant with data access as a system that can be manipulated by untrusted content.
  • Scope Copilot and agent permissions to the minimum data and actions genuinely required.
  • Log and monitor agent tool calls and outbound data flows, not just the prompts users type.
  • Red-team your AI deployments before launch and again after every major model or configuration change.

How AgentOffense helps: our AI agent penetration testing and prompt injection testing probe exactly these exfiltration and tool-abuse paths.

Source: eSecurity Planet.

← back to blog