logo

New attack turned Microsoft 365 Copilot into 1-click data theft tool

ID: ff6c79c8-8462-5f7c-94ec-e1940787e786

STIX ID: report--ff6c79c8-8462-5f7c-94ec-e1940787e786

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Bill Toulas

...
...

Varonis disclosed 'SearchLeak' (CVE-2026-42824), a critical chained vulnerability in Microsoft 365 Copilot Enterprise that lets an attacker craft a URL which instructs Copilot Search to retrieve sensitive content (emails, calendar items, OneDrive/SharePoint documents), embed that content in an image URL, and use Bing’s image fetch (SSRF) to exfiltrate the data; Microsoft has patched the issue and no mitigation action by users is required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.