One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
ID: a7b4b6d7-57b5-572a-8030-596e73d04565
STIX ID: report--a7b4b6d7-57b5-572a-8030-596e73d04565
Feed Name: The Hacker News
Threat Score
**SearchLeak:** Varonis chained a prompt-injection in Copilot Enterprise Search with a streaming sanitizer race and a CSP allowlist to exfiltrate mailbox, calendar and indexed files via Bing image fetches; Microsoft assigned CVE-2026-42824 and mitigated the flaw server-side, and Varonis published a PoC with no observed exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
