logo

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

ID: a7b4b6d7-57b5-572a-8030-596e73d04565

STIX ID: report--a7b4b6d7-57b5-572a-8030-596e73d04565

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

**SearchLeak:** Varonis chained a prompt-injection in Copilot Enterprise Search with a streaming sanitizer race and a CSP allowlist to exfiltrate mailbox, calendar and indexed files via Bing image fetches; Microsoft assigned CVE-2026-42824 and mitigated the flaw server-side, and Varonis published a PoC with no observed exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.