Minh Phu | Tech & AI[verified]@ChauPhu999Patch
Microsoft issued a patch on 18/8 for CVE-2026-24301 (CoSnitch), urging Windows users to update promptly to mitigate potential data leakage.
Aikido Community Japan[verified]@AikidoCommJPPatch
Microsoft has fixed CVE‑2026‑24301 in Microsoft Copilot, detailing two attack paths involving malicious links and memory persistence; no active exploitation has been confirmed yet, and users are advised to review Copilot memory and linked services for potential contamination.
Clint Gibler[verified]@clintgiblerDisclosure
The statement announces a newly disclosed Microsoft Copilot vulnerability (CVE-2026-24301) that permits data exfiltration via a hidden parameter, linking to a demonstration but providing no exploit code or patch details.
DFIR Radar[verified]@DFIR_RadarPatch
The post discloses the CVE-2026-24301 details, notes the official patch date, confirms no in‑the‑wild exploitation, and provides technical description of the flaw chain.
فيصل بن أحمد | خبير تقني[verified]@b_muf9General
The post alerts to CVE‑2026‑24301 in Microsoft Copilot, highlighting a meta‑hacking technique that expands the attack surface as AI privileges increase. No PoC, exploit code, patch, or detailed technical data are supplied.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses a command injection vulnerability (CVE‑2026‑24301) in Microsoft Copilot Web that permits unauthenticated attackers to execute commands and leak information.
Devsec AI[verified]@devsec_aiDisclosure
The tweet reports the discovery of CVE-2026-24301 in Microsoft Copilot, noting undocumented autorun behavior and OAuth leakage, and mentions that a patch was released after eight months. No PoC or exploit details are provided.
Kevin Kaminski[verified]@kkaminskPatch
CVE-2026-24301, a data exfiltration vulnerability via crafted link, has been patched server‑side with no client update needed.