Claimant scorecard · AERS v2.1 · Calibrating
Varonis Threat Labs & Microsoft
1 claim tracked in the Responsibility Ledger. 1 pending grade.
AERS
—
Insufficient closed grades
Pending
1
Open horizons
Closed
0
Graded outcomes
First tracked
Aug 24, 2026
Open horizons
Varonis Threat Labs & Microsoft: Disclosed August 18, 2026, CVE-2026-24301, a critical vulnerability in Microsoft Copilot Personal allowing one-click silent data exfiltration from connected OAuth accounts via an undocumented autorun parameter that researchers discovered by repeatedly questioning Copilot about its own constraints until it mapped its internal architecture, with Microsoft shipping patches the same day after an eight-month disclosure window
About this scorecard
The AI Execution Risk Score (AERS) is a 0-100 metric quantifying the gap between Varonis Threat Labs & Microsoft’s public AI claims and demonstrated delivery. Higher AERS = stronger track record. Each claim above is drawn from a primary source linked in the original Ledger entry; the horizon date is when the claim becomes graded under the published methodology. Materiality is the editor’s assessment of the claim’s formality from 1 (PR statement) to 5 (earnings call or SEC filing).
AERS v2.1 · Methodology in active calibration · Not investment advice.