Varonis
Sources: Varonis (homepage) · CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower · SearchLeak · Reprompt
Data security posture management (DSPM) vendor, listed alongside Cyera and BigID as one of the DSPM incumbents extending into AI-feed monitoring (Oversharing Controls) and named in Gartner’s “Agent security and risk specialists” segment of the Guardian Agents Market Guide (Guardian Agent).
Varonis Threat Labs is the vendor’s offensive-research arm and the credited discoverer of CoSnitch (CVE-2026-24301), a one-click Microsoft Copilot Personal vulnerability chain disclosed to Microsoft in December 2025 and patched August 18, 2026. Varonis states CoSnitch is the third Microsoft Copilot flaw the unit found in 2026, after Reprompt — Copilot Personal, no disclosed CVE, the q URL parameter pre-fills a prompt that still needs the victim to press Enter — and SearchLeak (CVE-2026-42824, updated June 15, 2026) — Microsoft 365 Copilot Enterprise, chaining the same q-parameter injection with an HTML rendering race condition and an SSRF through Bing’s CSP-allowlisted image-search endpoint to exfiltrate mailbox, calendar, and file data through image-embedded requests. Varonis states the pattern common to all three is that one click on a legitimate-looking link is enough; the specific mechanism after that click differs in each case (a manual Enter press, an SSRF chain, or CoSnitch’s silent autorun parameter). Neither Reprompt nor SearchLeak has its own wiki incident page as of this ingest.
Varonis’s disclosed discovery method for CoSnitch — repeatedly asking Copilot to justify why an attack should be impossible, and treating each refusal’s technical justification as reconnaissance — is documented on the incident page rather than here, since it is specific to that one finding.