Varonis

4 items · Defense 4 · all entities

Varonis discloses CoSnitch, a one-click Microsoft Copilot Personal flaw chain that could silently exfiltrate data from connected apps

Varonis Threat Labs disclosed CoSnitch, three chained weaknesses in Microsoft Copilot Personal that together let a single crafted link run a prompt with no user interaction, pull data from connected OAuth services such as Gmail, Google Drive and Calendar, and plant persistent instructions through indirect prompt injection. Varonis said it found no evidence of exploitation in the wild and that Microsoft shipped fixes on August 18, 2026, roughly eight months after the December 2025 report; the firm found the chain by getting Copilot to describe its own architecture, and it was Varonis's third Copilot flaw of 2026 after Reprompt and SearchLeak.

Reported by researchersVaronis Threat Labs ↗ ·

Researchers show Atlassian's Rovo AI assistant could be tricked into exfiltrating Jira and Confluence data

Varonis Threat Labs and PromptArmor separately disclosed that Atlassian's Rovo AI assistant could be driven by indirect prompt injection to collect Jira and Confluence data the signed-in user can access and send it to an attacker-controlled server without a separate approval step. Varonis's URL-parameter path, which it called RovoBlast, was patched server-side on July 8; PromptArmor's content-injection path was still unresolved as of its early-August write-up. No CVE was assigned.

Reported by researchersVaronis / PromptArmor (via The Hacker News) ↗ ·

Black Hat USA 2026 vendor announcements centre on AI agent runtime protection, discovery and least-privilege enforcement

SecurityWeek's three-part roundup of Black Hat USA 2026 announcements documents a concentrated wave of defensive products aimed at securing AI agents, including Cyera Agent Guardian and Menlo Security MARS for prompt-injection and exfiltration protection, KnowBe4 Agent Risk Manager and Mimecast Agent Risk Center for agent discovery and behaviour monitoring, Varonis intent-based access control and Zero Networks least-agency enforcement for constraining agent permissions, and Acalvio Deception Guardrails for honeytokens targeting agentic environments. Legit Security's VibeGuard 2.0 and Sysdig Secure AI specifically target AI coding agents such as Claude Code, Cursor and GitHub Copilot.

Reported by pressSecurityWeek ↗ ·

One permission was enough to plant persistent code inside Google Dialogflow CX agents

Varonis reports that the single dialogflow.playbooks.update permission, which can be scoped at project level, allowed malicious Python to be injected into a Dialogflow CX agent's Code Blocks and run without restriction, silently exfiltrating conversation data and manipulating agent responses while staying invisible to Cloud Logging; because Code Blocks ran in a shared execution environment, one compromised agent could reach others in the same project. Varonis also found a VPC Service Controls bypass and metadata-service exposure of Google service account credentials; it reported the flaw in November 2025, Google issued an initial update in April 2026 and fully resolved it in June 2026, and Varonis says it is “not aware of any exploitation in the wild before Google's patch release.”

Reported by researchersVaronis Threat Labs ↗ ·