Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit
S5 #4

Copilot Told Hackers How to Hack Itself + GitHub Goes Dark for 7 Hours + ChatGPT Drops Reddit

Microsoft took 233 days to patch CoSnitch (CVE-2026-24301), a one-click Copilot exploit rated 8.8 that reads your Gmail, Drive, and Calendar and writes attacker instructions into permanent memory — surviving a password change, new tokens, and a full device wipe. Varonis found it by asking Copilot to explain why the attack was impossible. Copilot mapped its own architecture and volunteered the undocumented parameter.
Martin Reynolds and Adam Arellano are joined by Matthew Tanner — 30 years shipping software, from NHS critical systems to national-scale financial redress — for the exploit Microsoft thought it had fixed in February, GitHub's seven-hour outage, and an AI agent that broke into a gym's booking system while trying to reserve a Pilates class.
Also in this episode: ChatGPT's use of the site: operator jumped roughly 46x in a single day, collapsing Reddit's share of citations and an entire agency business with it. And Stripe reportedly paying $7.5B for OpenRouter — a company whose whole pitch was that it prevents vendor lock-in.

Matthew Tanner — Founder, City Software · SaaS Architecture & Fractional CTO https://www.linkedin.com/in/matt7?originalSubdomain=uk 
HOSTS
ShipTalk is brought to you by Harness — https://www.harness.io/
New episode every other Wednesday — https://shiptalk.io/