2026-10-11 17:11 UTC

Independent testing and Microsoft’s response will determine whether Copilot disclosed hidden system input in a way that enabled practical compromise and required stronger interface or secret-handling protections.

state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security prompt-injection copilotMicrosoft

What is this?

The case concerns a reported Microsoft Copilot vulnerability called “CoSnitch” (CVE-2026-24301), allegedly disclosed by Varonis Threat Labs, in which researchers induced Copilot to reveal hidden system input and used that disclosure in a practical attack. The supplied search snippets do not independently document CoSnitch, its mechanics, Microsoft’s response, or a patch; they instead establish that other Copilot prompt-injection flaws, including EchoLeak and SearchLeak, have enabled or risked enterprise-data exfiltration. Microsoft’s documentation says Microsoft 365 Copilot uses layered safeguards, but the material is too thin to confirm this case’s specific claims or whether it required stronger interface or secret-handling protections.

Why it matters to Scott

Scott already argues in Architecture, Not Vibes and SiloOS that secrets must remain outside model context behind deterministic, tokenised boundaries, so the alleged Copilot disclosure adds no new position yet. If independently confirmed as a practical compromise—or if Microsoft responds with stronger structural secret isolation—it would provide a concrete enterprise-scale test and publishing receipt for those actively implemented claims.
ip:framework.architecture-not-vibesip:framework.siloosip:concept.proxy-mediated-tokenisationdev:project.silo-osradar:person.microsoftradar:concept.prompt-injectionradar:previous-token-prompt-reconstruction
queries asked of Scott's wikis
  • prompt injection as a security boundary
  • system prompts and secrets handling
  • agent interfaces and capability isolation
  • untrusted context in RAG systems
  • Copilot enterprise security model
  • agent data exfiltration defenses

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditMicrosoft Copilot reveals secret input that allowed it to be hacked
singularity
JackFisherBooks90
🟧 echo.blog ⭐Varonis Threat Labs’ primary disclosure of “CoSnitch,” CVE-2026-24301. It says researchers used “meta-hacking” to get Copilot to reveal the Varonis——

Interpretation history

Decision trace