A One-Click Copilot Leak and Zombie Visa Cards (08/18/2026)
- › CoSnitch, tracked as CVE-2026-24301, chains three Copilot Personal flaws so a single link runs an attacker's prompt and pulls mail, calendar, Drive files, and chat history.
- › The prompt finishes even if the victim closes the tab, and Microsoft patched it today after a December 2025 report from Varonis.
- › Researchers revived expired Visa cards at contactless terminals because that configuration does not sign the expiry date the terminal reads.
- › A crew calling itself Ransom Busters emails ransomware victims claiming to hold their stolen data, asking $20,000 to $60,000.
- › CISA gave federal agencies three days to patch an actively exploited remote code execution flaw in Ray.
Two of today’s stories are about a signature nobody checked. Visa’s contactless configuration hands the terminal an expiry date that sits outside the card’s digital signature, so researchers put a dead card back to work. Copilot Personal had an undocumented URL parameter that ran a stranger’s prompt against your mailbox, and the researchers found it by asking Copilot about its own restrictions until it told them.
Top 5 Critical Security Alerts
1. One Link Made Copilot Personal Read Your Mail Back to an Attacker
Varonis Threat Labs chained three flaws in Copilot Personal, the consumer product, into CVE-2026-24301. An undocumented autorun URL parameter paired with a query parameter executes an attacker’s prompt with no user interaction, and the prompt runs to completion even if the victim closes the tab immediately. Testing reached message bodies, subject lines, and sender metadata in email, calendar titles and attendees, Google Drive files, chat history, and saved memory instructions, with persistent writes back into memory. Reported in December 2025 and patched today. No exploitation has been seen in the wild. The Hacker News
Operator Note: Eight months from report to patch on a one-click mailbox read. The part to carry into your own environment is the memory write, because that outlives the session and the tab. An assistant that remembers a poisoned instruction keeps acting on it after every trace of the original link is gone. Ask which of your approved assistants hold connected app scopes and persistent memory at the same time, and whether anyone has ever reviewed what is sitting in that memory.
2. Researchers Brought Expired Visa Cards Back to Life
At USENIX Security 2026, Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza demonstrated a proxy attack on contactless terminals that alters the expiration date in transit. In the Visa configuration tested, the expiry date the terminal reads is not covered by the card’s digital signature, so the terminal evaluates one date while the issuer checks another. Mastercard, American Express, and Discover configurations resisted it. Success varied by issuing bank. Visa was notified in May 2025 and again in December 2025, and neither Visa nor the banks have confirmed a mitigation. The Register
Operator Note: Fifteen months of notice with no confirmed fix, on a card network most of your customers carry. If you run retail or hospitality, the practical exposure is chargebacks on transactions your terminal approved correctly, and the reconciliation question is whether your processor can even show you the expiry date that was presented against the one on file.
3. A Crew Is Extorting Ransomware Victims a Second Time
Ransom Busters emails organizations that have already been hit, claims to have breached the ransomware group’s servers and found their stolen data, and offers to delete it for $20,000 to $60,000. GuidePoint’s research team tracked the activity across DragonForce, Settra, and Anubis incidents and found identical tooling, a shared backdoor password, and one reused hostname, which points to a single operator who is most likely an affiliate reselling access to the same victims rather than an outsider who breached anybody. The Hacker News
Operator Note: This lands on an organization already three weeks into an incident, exhausted, and desperate for the data to be gone. That is a targeting decision. Write into your response plan now that all post-incident contact routes through counsel, so the person who opens that email on a bad Thursday is not the person deciding whether to pay it.
4. CISA Gives Federal Agencies Three Days on an Exploited Ray Flaw
CISA added an actively exploited remote code execution flaw in Ray, the distributed compute framework, and set a three-day remediation deadline for federal agencies rather than the usual weeks. The flaw can be triggered through a browser. The Register
Operator Note: A three-day directive is CISA saying the exploitation is broad and the consequence is severe. Ray runs in machine learning infrastructure that often sits outside the asset inventory your patching program works from, because a data science team stood it up. Go ask whether you run it before deciding you do not.
5. TWINLOOT Runs Entirely Inside Microsoft’s Cloud
TWINLOOT abuses SharePoint and Teams to steal credentials and move between networks without ever standing up infrastructure of its own. Every stage lives in services the target already trusts and already permits. Dark Reading
Operator Note: There is no malicious domain to block and no unusual destination to alert on, because the traffic goes where your traffic already goes. Detection here has to come from behavior inside the tenant rather than from the network edge, which is a different tooling budget than most organizations have allocated.
Additional Security Alerts
Threat Intelligence
- CISA has identified more than 200 Medusa ransomware victims in the past year: The volume puts it among the more productive operations currently running. The Record
- A Windows Task Host flaw is now being exploited by ransomware gangs: CISA flagged the shift from proof of concept to active use. BleepingComputer
- Three quarters of ransomware attacks are hitting mid-market firms: Large enough to pay, small enough to lack a response team. Infosecurity Magazine
Security Breaches & Incidents
- The University of Texas at San Antonio took systems offline after a cyberattack: Student services are disrupted. Infosecurity Magazine
- Berlin cut two state ministries off the government network after a breach: Containment by disconnection, which tells you something about the confidence in segmentation. The Record
- Clop built a custom web shell for its Windchill data theft campaign: Purpose-built tooling for one product line. BleepingComputer
Security Tools & Best Practices
- Apple patched an image-processing hole well suited to spyware delivery: The class of flaw that makes a zero-click chain possible. The Register
- A NASA ground control software flaw allows unauthenticated commands: Command authority without authentication, in software built to move spacecraft. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.