CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
Varonis disclosed in August 2026 a three flaw chain in which one click made Microsoft Copilot execute injected instructions, collect mail, calendar entries and files from connected services, and send them out as ordinary web requests. The instruction also wrote itself into the user's memory store, so it ran again in every later session until the user deleted it by hand.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0021
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
- One click on a link that looks legitimate was enough to start the chain.
- The agent pulled messages containing credentials, calendar entries and files from connected services.
- Exfiltration used ordinary outbound web requests that are indistinguishable at the network layer from a legitimate fetch.
- The research summarises the chain as three vulnerabilities, one click and no anomalous signals.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Injected text ran with the identity and reach of the signed in user.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- AuthorizationSilent
- The agent's connected service reach was inherited wholesale by the injected instruction.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- LimitsSilent
- Nothing bounded which services the instruction could query or where the results could go.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- Human approvalSilent
- One click on a legitimate looking link was the entire user interaction.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- Logging and auditSilent
- This is the sharpest finding in the ledger on logging: the exfiltration produced no anomalous signal and looked like a normal fetch.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- RevocationSilent
- The vendor patched the chain, but removing the implant from a user's memory required that user to know to delete a memory entry.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
- AccountabilityStated
- A CVE, a named research team and a printed disclosure timeline.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
What it changes
For a team deploying an agent
Agent memory is state an attacker can write to, and it survives the patch. Treat revocation as including memory: know where your agent's persistent memory lives, be able to inspect it, and be able to clear it for every user at once. An incident response plan that patches the flaw and leaves the implant in place has not ended the incident.
Sources
What this record was verified against
- Varonis Threat Labs, CoSnitchPrimary · 18 August 2026
Related
Records that sit beside this one
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
United States · verified 15 September 2026
The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0021 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), cosnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory
- MLA
- "CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.