Microsoft Just Fixed a Copilot Bug That Could Read Your Email
Microsoft pushed out a patch Tuesday for a flaw in Copilot, and I think small business owners should read about this one. Not because the bug is still dangerous, it's fixed, but because of what it says about how we've all been wiring these tools into our accounts without really thinking about it.
Here's what happened. A security team called Varonis Threat Labs found a hole in the personal version of Microsoft Copilot. They nicknamed it CoSnitch, and it got the official label CVE-2026-24301 if you want to go look it up yourself. The short version is somebody could send you a link, you click it one time, and a hidden instruction rides along with that link and runs inside your own logged in Copilot session. No download. No fake login page asking for your password. One click on a link that looks normal.
And because it was running as you, it could reach whatever you'd connected. In the writeup that meant Gmail, Google Drive, Google Calendar, plus your Copilot chat history and anything Copilot had saved in its memory about you.
Microsoft patched it on August 18. Varonis says they found no sign anybody was actually using it out in the wild before the fix shipped. So if you use Copilot, you're fine. There's nothing for you to install.
But think about the shape of that for a second.
The bug was never really the point
Varonis reported this to Microsoft back in December. The patch showed up about eight months later. That's a long window for something that only needed one click to work, and it's a decent reminder that the company who built your AI tool and the companies who run the accounts it's plugged into are not always moving at the same speed on the same problem.
What actually matters here is the connection list. Almost every AI assistant now asks to hook into your email, your calendar, your files, sometimes your CRM. Most people say yes during the first week they're trying it out, because that's when it's exciting and you want to see what the thing can do. Then they never think about it again.
I've sat with owners in Toledo and Perrysburg who honestly could not tell me what their AI assistant had access to. Not because they were careless about it. They clicked approve back in March and moved on with their day, same as anybody would.
What I'd go do this week
Open whatever AI tool you use the most, Copilot, ChatGPT, Gemini, Claude, doesn't matter which, and find the connections or integrations page. Every one of them has it, usually buried a couple layers deep in settings. Look at what's actually on that list.
Then ask two things. 1: do I still use this connection, or did I turn it on once to test it and forget? 2: if somebody got into this tool tomorrow, what would they be able to read?
Turn off anything that fails the first question. For anything that passes but makes you uneasy on the second one, decide whether the time it saves you is worth the tradeoff. Sometimes it clearly is. Your calendar is probably fine. Handing over your entire client email history is a different conversation, and it's one worth having out loud with whoever runs your operations.
This is the same thing I cover in my workshops when we talk about pasting sensitive stuff into a chat box, just one layer up. What you type in is only half of it. The other half is what you gave the tool standing permission to go read months ago.
The part nobody wants to hear
There's going to be another one of these. Not maybe. These tools are new, they're getting built fast, and by design they sit right on top of your most sensitive accounts. That doesn't mean stop using them. I use them all day and they've made me faster at my actual work.
It just means the connection list is now something you check on purpose, the way you check who still has a key to the building after somebody leaves.
Ten minutes, once a quarter. That's the whole ask.
I run AI workshops and one-on-one AI consultations for businesses around Toledo, Northwest Ohio, and Southeast Michigan, and going through what your team has already connected is usually the first thing we do. If you want a second set of eyes on it, send me a note and I'll take a look.
Email Jayson