ET EXPLOIT Microsoft Copilot One-Click Auto Execution Prompt (CVE-2026-24301)
Sourceet/open
Fileemerging-exploit.rules
CreatedAugust 25, 2026
UpdatedAugust 25, 2026
Classificationattempted-user
alert smtp any any -> [$HOME_NET,$SMTP_SERVERS] any (msg:"ET EXPLOIT Microsoft Copilot One-Click Auto Execution Prompt (CVE-2026-24301)"; flow:established,to_server ; content:"copilot.microsoft.com"; fast_pattern; content:"q|3d|"; content:"autorun|3d|"; pcre:"/copilot.microsoft.com\x2f[^\s]*?(?:[\x3f\x26](?:q\x3d|autorun\x3d(?:1|[tT][rR][uU][eE]))[^\s]*?\x26(?:q\x3d|autorun\x3d(?:1|[tT][rR][uU][eE])))/" ; reference:url,www.varonis.com/blog/cosnitch ; reference:cve,2026-24301 ; classtype:attempted-user; sid:2071788; rev:1; metadata:attack_target Server, created_at 2026_08_25, cve CVE_2026_24301, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2026_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
References
Metadata
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!