Date

Read time

The Copilot Bug That Needed No Click At All

Microsoft shipped a patch on 18 August for a vulnerability in Copilot that most of its business customers will never hear about, which is exactly the problem. Security researchers at Varonis called it "CoSnitch." A single malicious link, sent to someone whose Copilot was connected to Gmail, Drive and Calendar, could quietly exfiltrate that data. No click confirmation. No warning dialogue. The flaw had been flagged to Microsoft back in December 2024, and once the fix was properly under way, it still took roughly eight months to close it fully.

None of this makes Copilot uniquely dangerous. Every AI assistant that connects to your inbox, your files or your calendar is, by definition, creating a new route into that data, and the vendor building it can be slow to close a gap even after being told about it. The lesson isn't "avoid Copilot." It's that "enterprise-grade" was never the same claim as "immediately safe by default," and it's worth knowing the difference before you connect anything to anything.

Why this matters more for agencies than most

An agency's inbox is rarely just its own. It holds client briefs, campaign assets, invoices, introductions to other people's contacts, sometimes access to a client's own systems. When an AI assistant gets connected to that inbox to save time on drafting, summarising or scheduling, the assistant inherits the blast radius of everything it touches. A vulnerability like this one isn't really a story about one email account. It's a story about every client relationship that account touches.

That's not a reason to avoid connecting AI tools to email and calendars. The productivity case for doing so is real, and plenty of agencies are already seeing the benefit. It's a reason to know, specifically, what each tool is connected to, what data it can reach, and what happens if that connection is ever exploited. Most businesses using Copilot, ChatGPT plugins, or Gemini's Workspace integrations couldn't answer that question today if asked.

What the Diagnostic would have caught

This is precisely the territory the Governance dimension of the AI Accelerator Diagnostic exists to map. Not "is AI allowed here," but a plainer question: what does everyone in this business need to know before using AI in real work, and does anyone actually know what's connected to what. Most SMEs and agencies have never mapped it. The tools were switched on by whoever set them up, permissions were granted at whatever level felt convenient at the time, and nobody has revisited the question since.

The useful exercise isn't a lockdown. It's an inventory: which AI tools are connected to which accounts, what each one can see, and who signed off on that access. For most businesses this takes an afternoon, not a security review, and it turns "we assume it's fine because Microsoft built it" into "we know exactly what this can reach."

The quieter point

The gap between when Varonis reported the flaw and when Microsoft closed it says something worth sitting with. Even a vendor with enormous security resources didn't move quickly on this. Smaller businesses connecting AI tools to sensitive systems don't have the luxury of assuming someone else is watching the door. Knowing what's connected, and treating that knowledge as something to check rather than assume, is the more reliable habit.

That's the whole idea behind going wisely with AI. Not fear of the tools, and not blind trust in them either. Just the discipline of knowing what you've actually connected before you decide it's safe.

Go wisely.

Source: Varonis / Microsoft security advisory, CVE-2026-24301, patched 18 August 2026.