ZeroHour
Vendor

Varonis

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

A 2026 scorecard ranks DSPM tools with Wiz and Cyera tied first, documenting consolidation via Palo Alto, Rubrik, Proofpoint, and CrowdStrike acquisitions.

The article ranks ten DSPM platforms: Wiz and Cyera tie at 8.7/10, followed by BigID at 8.5 and Securiti at 8.4, scored on discovery breadth, classification accuracy, access context, remediation, and value. It highlights heavy market consolidation, noting Dig Security was acquired by Palo Alto Networks, Laminar by Rubrik, Normalyze by Proofpoint, and Flow Security by CrowdStrike. Buyers are advised to purchase from current owners and confirm post-acquisition integration state.

Cyber Security News · 2h agoIndustry

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis discloses CoSnitch (CVE-2026-24301), three Microsoft Copilot Personal flaws enabling one-click exfiltration of connected-app data; patched August 18, 2026.

Varonis Threat Labs found that an undocumented autorun=1 parameter, paired with the q parameter, lets an attacker-supplied prompt run automatically on page load in a victim's authenticated Copilot session, then exfiltrate data from connected services such as mail, calendar, Google Drive, chat history and the memory store via Copilot's built-in URL fetch to an attacker webhook. A separate memory-poisoning path through web summarization lets a crafted page persist attacker instructions in the user's memory, surviving password changes, session revocation and device re-enrollment. Microsoft shipped patches on August 18, 2026, tracked as CVE-2026-24301, and Varonis found no evidence of in-the-wild exploitation. The flaws were found via 'meta-hacking', asking Copilot itself to reveal the autorun parameter and its protections.

Related CVEs

  • Command Injection in Microsoft Copilot Allows Information Disclosure
    CVE-2026-24301 is a command injection flaw (CWE-77) in Microsoft Copilot in which special elements are not properly neutralized before being used in a command, allowing an unauthorized attacker to send commands over a network. Per the CVSS vector (AV:N/AC:L/PR:N/UI:R), exploitation requires no privileges but does require user interaction, which aligns with the related headline reporting that a single click in the Copilot personal experience could trigger exfiltration of data from connected apps. The vulnerability is rated 8.8 (high), and while the description emphasizes information disclosure, the CVSS base score rates confidentiality, integrity, and availability impacts all high. Affected users are those using Microsoft Copilot; the source data does not specify version ranges, and the headline suggests the personal/consumer Copilot experience is implicated. No exploitation is currently known: there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS puts 30-day exploitation probability at 2.2% (82nd percentile).
    · Microsoft Copilotmass
  • Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over
    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
    · microsoft 365 copilot

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.