New attack turned Microsoft 365 Copilot into 1-click data theft tool
ID: ff6c79c8-8462-5f7c-94ec-e1940787e786
STIX ID: report--ff6c79c8-8462-5f7c-94ec-e1940787e786
Feed Name: Bleeping Computer
Threat Score
Varonis disclosed 'SearchLeak' (CVE-2026-42824), a critical chained vulnerability in Microsoft 365 Copilot Enterprise that lets an attacker craft a URL which instructs Copilot Search to retrieve sensitive content (emails, calendar items, OneDrive/SharePoint documents), embed that content in an image URL, and use Bing’s image fetch (SSRF) to exfiltrate the data; Microsoft has patched the issue and no mitigation action by users is required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
