SearchLeak: New Attack Turned Microsoft 365 Copilot into 1-Click Data Theft Tool
ID: d00e206e-b70d-5854-9192-088dc3c01026
STIX ID: report--d00e206e-b70d-5854-9192-088dc3c01026
Feed Name: CosmicBytez Labs
**SearchLeak** is a critical chained vulnerability in Microsoft 365 Copilot Enterprise that enables data exfiltration (mailbox, OneDrive, SharePoint) to an attacker-controlled endpoint by a single specially crafted URL; the attack abuses Copilot's authorized access and can evade traditional DLP and security controls. The report details the attack steps, detection via Copilot audit logging, recommended mitigations (restrict Copilot access, enable Purview logging, harden conditional access), and notes Microsoft is investigating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
