Copilot explained its own safeguard until researchers found the hole.
CoSnitch turned a crafted link into automatic prompt execution, connected-data access and an exfiltration path—after the assistant revealed the missing parameter.
CoSnitch turned a crafted link into automatic prompt execution, connected-data access and an exfiltration path—after the assistant revealed the missing parameter.
Risk becomes easier to manage when identity, authorization, boot state, storage and recovery are treated as evidence—not vibes.
A one-click flaw redirected Copilot’s legitimate access—and the assistant itself disclosed the undocumented mechanism that made it possible.
A package-proxy zero-day broke the first boundary; broad credentials and infrastructure trust made the intrusion much worse.
What Microsoft now acknowledges, what individual reports preserve, and how to test without discarding the evidence.
Match logs can reveal a sudden change in playstyle, but suspicion is not proof of account misuse.
More permissive capabilities arrive with identity, authorization, monitoring and separate approval.
Provenance signals can support a claim, but they do not become universal proof of authorship.
Boot Manager, recovery and a kernel crash demand different evidence and different responses.
Identify the stale loader and remove only the proven phantom entry.
Protect the original, account for encryption and verify the destination before declaring success.
Put evidence gathering, reversibility and risk checks ahead of generated commands.