Responsibility LedgerAppend-only · Dated · Signed

Claimant scorecard · AERS v2.1 · Calibrating

Varonis Threat Labs & Microsoft

1 claim tracked in the Responsibility Ledger. 1 pending grade.


AERS

Insufficient closed grades

Pending

1

Open horizons

Closed

0

Graded outcomes

First tracked

Aug 24, 2026

Open horizons

  • Varonis Threat Labs & Microsoft: Disclosed August 18, 2026, CVE-2026-24301, a critical vulnerability in Microsoft Copilot Personal allowing one-click silent data exfiltration from connected OAuth accounts via an undocumented autorun parameter that researchers discovered by repeatedly questioning Copilot about its own constraints until it mapped its internal architecture, with Microsoft shipping patches the same day after an eight-month disclosure window

    Grade by Feb 24, 2027· 6 months·Entry 090·Materiality 3/5

About this scorecard

The AI Execution Risk Score (AERS) is a 0-100 metric quantifying the gap between Varonis Threat Labs & Microsoft’s public AI claims and demonstrated delivery. Higher AERS = stronger track record. Each claim above is drawn from a primary source linked in the original Ledger entry; the horizon date is when the claim becomes graded under the published methodology. Materiality is the editor’s assessment of the claim’s formality from 1 (PR statement) to 5 (earnings call or SEC filing).

AERS v2.1 · Methodology in active calibration · Not investment advice.