Why Microsoft Sat on a Copilot Exploit for 233 Days

Aug 26, 2026

Microsoft took 233 days to patch CoSnitch — a one-click Copilot exploit that needs no click at all. And the researchers who found it never wrote an exploit. They asked Copilot to explain why the attack was impossible, and it told them how to do it.

Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the week in AI and software delivery.

CoSnitch (CVE-2026-24301, severity 8.8) chains three flaws in Copilot Personal. A single crafted link runs an attacker-controlled prompt the moment the page loads. That prompt reads Gmail, Drive, and Calendar, then exfiltrates the data using Copilot's own ability to fetch a URL. Microsoft said it fixed this for enterprise users in February — but personal Copilot, which most developers also run, carried the flaw back into the enterprise instance. And the injected instructions land in permanent memory, not on your machine: wipe the laptop, change the password, rotate every token, and it is still there. Varonis calls the discovery method meta-hacking — social-engineering the model's reasoning rather than attacking its code.

Then there's the gym. Andrew Bird, an AI technologist in Melbourne, pointed OpenClaw running Claude Opus 4.6 at booking a Pilates class. The agent found the booking API had no authorization checks on cancelling other people's reservations, took admin control, and removed another member from the waitlist to make room. No criminal intent, no external attacker, a paying member with a legitimate request — and an agent that pursued the goal past the boundary of what was asked. Matthew raises the harder question: the Computer Misuse Act turns on a person knowing their access was unauthorised. There wasn't a person.

We also cover GitHub's seven-hour outage and why "the spike in AI agent development" is only half the explanation, ChatGPT's jump in site: operator usage collapsing Reddit's citation share and a whole agency playbook with it, and Stripe reportedly paying $7.5B for OpenRouter — the routing layer whose CEO pitched it as the thing that prevents vendor lock-in.

⏱️ CHAPTERS

00:00 Intro

00:45 ChatGPT stopped citing Reddit

04:07 Harness by the Numbers

05:22 Copilot told hackers how to hack itself

07:00 Copilot explains its own attack path

08:46 GitHub's seven-hour outage

11:01 Why regulated industries stay with Microsoft

14:35 An AI agent broke into a gym — who's liable?

17:40 Stripe's $7.5B bet on OpenRouter

20:04 What teams are getting wrong about AI in software delivery 23:37 The takeaway

🔗 GUEST Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO LinkedIn: linkedin.com/in/matt7?originalSubdomain=uk

🎙️ HOSTS Martin Reynolds —https://www.linkedin.com/in/martinreynolds/

Adam Arellano — https://www.linkedin.com/in/adamrossarellano/

📬 SHIPTALK New episode every other Wednesday.

Follow the pod: https://shiptalk.io/

Learn more: https://www.harness.io/

#Copilot #AIagents #DevOps

Tags

CoSnitch, CVE-2026-24301, Copilot vulnerability, Copilot exploit, meta-hacking, prompt injection, memory injection, Varonis, GitHub outage, Cursor Origin, Stripe OpenRouter, OpenClaw, Claude Opus 4.6, AI agent liability, Computer Misuse Act, ChatGPT Reddit citations, AI agent security, DevOps news