Skip to main content
VerifiedExfiltration

CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session

Varonis disclosed in August 2026 a three flaw chain in which one click made Microsoft Copilot execute injected instructions, collect mail, calendar entries and files from connected services, and send them out as ordinary web requests. The instruction also wrote itself into the user's memory store, so it ran again in every later session until the user deleted it by hand.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0021
Kind
Exfiltration
Jurisdiction
United States
Last verified
Added
  • The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
  • One click on a link that looks legitimate was enough to start the chain.
  • The agent pulled messages containing credentials, calendar entries and files from connected services.
  • Exfiltration used ordinary outbound web requests that are indistinguishable at the network layer from a legitimate fetch.
  • The research summarises the chain as three vulnerabilities, one click and no anomalous signals.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Injected text ran with the identity and reach of the signed in user.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
AuthorizationSilent
The agent's connected service reach was inherited wholesale by the injected instruction.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
LimitsSilent
Nothing bounded which services the instruction could query or where the results could go.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
Human approvalSilent
One click on a legitimate looking link was the entire user interaction.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
Logging and auditSilent
This is the sharpest finding in the ledger on logging: the exfiltration produced no anomalous signal and looked like a normal fetch.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
RevocationSilent
The vendor patched the chain, but removing the implant from a user's memory required that user to know to delete a memory entry.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.
AccountabilityStated
A CVE, a named research team and a printed disclosure timeline.Varonis Threat Labs, CoSnitch, primary source, 18 August 2026.

What it changes

For a team deploying an agent

Agent memory is state an attacker can write to, and it survives the patch. Treat revocation as including memory: know where your agent's persistent memory lives, be able to inspect it, and be able to clear it for every user at once. An incident response plan that patches the flaw and leaves the implant in place has not ended the incident.

Sources

What this record was verified against

  1. Varonis Threat Labs, CoSnitchPrimary · 18 August 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0021 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), cosnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session.
APA
GAGE (Global Academy of Generative-AI Education). (2026). CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory
MLA
"CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory.
Chicago
GAGE (Global Academy of Generative-AI Education). "CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0021-cosnitch-copilot-wrote-the-attack-into-its-own-memory

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.