• John Hammond
  • Posts
  • Cybersecurity Shenanigans #027: Copilot snitches on itself, GitLab's zero-click nightmare, and I made AI build a Minecraft mod šŸ”

Cybersecurity Shenanigans #027: Copilot snitches on itself, GitLab's zero-click nightmare, and I made AI build a Minecraft mod šŸ”

Here's this month's cybersecurity scoop.

šŸ‘‹ Hey friend,

The Hacker Summer Camp FOMO was almost too much to handle!

Thanks to everyone who stopped by the IoT Village at DEF CON and said hello. The JHT team kept sending pictures and updating me on the success of the event, and I couldn’t be more proud of the team we’ve assembled. What they did during Black Hat and DEF CON is truly stunning, and what we’ll do the rest of the year and into 2027 will be even better!

Before DEF CON was even halfway over, we gave out 200 shirts, 1,000 flyers and 4,000 stickers! We also bumped up the number of laptops to do our 2 free workshops (AKA, Extended Upskill Challenges) from 8 last year to 12 this year… and they were filled pretty much the entire time!

If you didn’t get a chance to do our 2 free mini-workshops, don’t fret. Check out the JHT section below for details on how to do them at home.

Speaking of missing out… When I heard that ALL of the flyers with a 20% off show only coupon code went so quickly, I felt horrible that not everyone got a chance to even hear about it. So… (and don’t tell Don 🤫) I added it to the JHT section below.

As always, thanks for being here!

— JH

News & Commentary

When You Just Ask the AI to Snitch on Itself šŸ¤–

This one’s equal parts funny, terrifying, and downright amusing.

Researchers at Varonis Threat Labs found something called CoSnitch (which is hilarious). They were able to trick a Microsoft Copilot instance into just…telling them about its architecture, thus showing security weaknesses. Innocent-sounding follow-up questions about URL structures and how it handles prompts, and Copilot is ready to hand over its own blueprint. šŸ’€

This led to the researchers finding an undocumented ?autorun=1 parameter that automatically executes embedded prompts when it’s tacked onto a query — guardrails and all. So now you've got a malicious link like copilot[.]microsoft[.]com/?q=<prompt>&autorun=1 that runs unauthorized actions inside their already-authenticated session the moment a victim clicks it. And from there, attackers could exfiltrate data from Gmail, Google Drive, Google Calendar, or even Copilot’s own memory; poison memory for future manipulation; or just do some good ol’ fashioned reconnaissance and disinformation.

This hit Copilot Personal specifically (enterprise customers were unaffected), and Microsoft's already shipped a fix as of August 18, 2026, tracked as CVE-2026-24301 with a CVSS of 8.8. Varonis reported it back in December 2025, so this was a good long responsible-disclosure runway before the public writeup. So far, there’s been no signs it was exploited in the wild.

The line from researcher Lior Adar is the one I keep coming back to:

Every enterprise AI assistant is basically a privileged insider with zero security awareness.

That's the mental model to build your defenses around going forward.

(((By the way, if you’d like to try tricking AI into telling you stuff, we made a game for that.)))

GitLab Has a Zero-Click Problem āš ļø

Buckle up, folks. This one’s rough. But patched. So there’s that. šŸ˜…

GitLab just patched CVE-2026-19478, a critical code-injection bug (with a CVSS score of 9.4 no less) housed in their GraphQL functionality. This was a zero-click vulnerability that required zero authorization, zero credentials, and zero user interaction to exploit. An attacker could just show up and manipulate or delete data on publicly accessible projects.

If you're running GitLab CE or EE on 18.2 through 18.10, or on 19.x before 19.0.8 / 19.1.6 / 19.2.4, beware: You're in the blast radius. GitLab.com and GitLab Dedicated customers are fine since those were already patched behind the scenes.

But here’s the part that makes our lives harder as defenders. GitLab sat on the technical details for 90 days after shipping the patch. The good news is that gave folks time to update, but it also put detection engineers behind. As one researcher put it, you can’t write a reliable signature for attack mechanics no one’s actually disclosed.

The takeaway: Patch your self-hosted GitLab instances now, don't wait for the technical writeup. If you can't patch immediately, get those instances behind a VPN or WAF and start watching your /api/graphql logs for anything weird.

Sponsor

Into the Breach is live. Episode 1 is on YouTube now.

You heard about it at Black Hat. Now it’s streaming. šŸŽ¬ļø

Into the Breach, OPSWAT’s cybersecurity docuseries hosted by MythBusters’ Kari Byron, takes you inside the real-world fight to protect the critical infrastructure we all rely on, from power grids and water systems to financial networks.

Episode 1 just dropped on YouTube, and this one’s for the community. If you’ve been wondering what all the buzz is about, now’s your chance to see it for yourself.

Go check it out! šŸ‘‡ļø

Email being clipped?

Here’s some actually helpful advice: You can view the email in your browser: https://johnhammond.beehiiv.com/p/cybersecurity-shenanigans-027.

(And as always, thanks for nothing, Clippy. šŸ’™)

Latest Content

// Full disclosure: I don't play Minecraft. I don't mod Minecraft. So naturally, I tried to build a Minecraft mod live with AI that turns open directories into explorable worlds. And…it went about as well as you'd expect. šŸ˜…

// Kali365 is a phishing-as-a-service platform bypassing MFA with device code phishing. In this video, I log into the backend panel and crack open the code. šŸ˜€

// In this one, I wanted AI to build and manage its own cyber deception engine, so I let Codex loose live to make it happen.

Just Hacking Training News šŸ¤“

August Course Release

A Home Lab is a must in learning AI & cybersecurity! This FREE hands-on course by Joram Stith is your ticket to self-hosting, research, data privacy & jobs.

NameYourPrice with a $0 Minimum!

A home lab is a must in learning AI and cybersecurity. PERIOD! From learning new technology to honing your technical skills, having your own lab provides a protected environment to learn and self-hosted apps for data privacy. More importantly, seeing your lab on your resume sets you apart from every other candidate vying for that perfect job you’re dying to get!

If you’re like most, you know how important it is, but you’re frustrated with finding 1000s of videos on YouTube that are inconsistent and piecemeal. If you’d love for an experienced professional to provide step-by-step instructions, then this hands-on course is for you!

NameYourPrice Minimum = $0!

Price = $50

This is a ā€œName Your Priceā€ course. Your options include:

  • Minimum Price = $0

  • Suggested Price = $50

  • Pay more to support our community efforts

That’s right! Knowing how crucial it is to have lab experience on your resume when starting your career, Joram insisted on making this course available for FREE for those who need it. The suggested price is still crazy low at just $50, but the NameYourPrice model allows a minimum price of $0.

DEF CON Free Workshops

Couldn’t make it to DEF CON? Saw us in the IoT Village, but all of the laptops were filled with hackers? No worries!

Both Free Workshops from this year as well as the 2 from last year are all online for free! They are NameYourPrice, so anything you can contribute helps us to deliver great content to the community.

Don’t Tell Don! 🤫

Use code DC20 for 20% Off Just Hacking Training

Excludes Already Discounted Bundles
Expires Midnight ET August 31

Suggested Courses

ā¤ļø Red Team

Blue Team šŸ’™

Courses in Production: Coding for Cybersecurity, Networking for Pentesters, Reverse Engineering, MADS Vol 4, Jr Network Pentest, and more!

Happy Hacking!

Social