Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Copilot Personal security update (CVE-2026-24301)

Security Patch Release
First reported
Last updated
Happening score
H score 18
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft shipped a security update for Copilot Personal tied to CVE-2026-24301, closing a flaw that could let a crafted link trigger a prompt inside a signed-in session and access connected-app data. The patch matters because the issue affected a consumer Copilot assistant with access to the user's authorized services. The release date was August 18, 2026.

Related Happenings

Microsoft Windows 10 KB5099539 extended security update

Security Patch Release
H score16 First: 14.07.2026 21:49 Last: 14.07.2026 21:49 Sources 1

About this happening: Microsoft released Windows 10 KB5099539, a security update bundle for Windows 10 ESU that rolls in July 2026 Patch Tuesday fixes for 570 vulnerabilities. The p...

Microsoft YellowKey patch release (CVE-2026-45585)

Security Patch Release
H score20 First: 11.06.2026 20:43 Last: 11.06.2026 20:43 Sources 1

About this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...

Microsoft June 2026 Patch Tuesday GreenPlasma and YellowKey fixes

Security Patch Release
H score15 First: 10.06.2026 02:11 Last: 10.06.2026 02:11 Sources 1

About this happening: Microsoft released June 2026 Patch Tuesday updates that fixed the GreenPlasma and YellowKey flaws, closing two previously disclosed issues in the Windows ecosystem...

Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498

Security Patch Release
H score44 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...

Latest development: 21.05.2026 12:52

Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.

Windows 10 KB5087544 extended security update

Security Patch Release
H score15 First: 12.05.2026 21:58 Last: 12.05.2026 21:58 Sources 1

About this happening: Microsoft released Windows 10 KB5087544 for Windows 10 ESU/LTSC systems, addressing May 2026 Patch Tuesday vulnerabilities and a Remote Desktop warnings issue....

Timeline

  1. 18.08.2026 20:47 2 articles · 2h ago

    Microsoft ships Copilot Personal patches for CoSnitch

    Mitigation Patch Update

    Microsoft shipped patches for CoSnitch, the Copilot Personal vulnerability set tracked as CVE-2026-24301. Varonis said the flaws could let a crafted link using autorun=1 and q trigger prompt execution inside a signed-in Copilot Personal session and silently pull data from connected apps.

    Show sources