PulseAugur
EN
LIVE 11:10:20

Critical "SearchLeak" vulnerability in Microsoft 365 Copilot allows data exfiltration

A critical vulnerability dubbed "SearchLeak" has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to exfiltrate sensitive data with a single click. The vulnerability chain, identified by Varonis Threat Labs, exploits three distinct weaknesses to gain access to emails, passwords, and indexed organizational files. Microsoft has since patched the backend vulnerability and disclosed it with a critical severity rating, noting that no administrator action is required for the fix. AI

IMPACT Exposes enterprise AI assistants to prompt injection risks, highlighting the need for robust security measures in AI integrations.

RANK_REASON Discovery of a specific vulnerability in a widely used enterprise AI product.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Critical "SearchLeak" vulnerability in Microsoft 365 Copilot allows data exfiltration

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Discovery of a specific vulnerability in a widely used enterprise AI product.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
100 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Logan ·

    CVE-2026-42824 SearchLeak: How M365 Copilot Became a One-Click Data Exfiltration Tool

    <p><strong>CVE-2026-42824, named "SearchLeak" by Varonis Threat Labs researchers who discovered it, is a critical three-stage vulnerability chain in Microsoft 365 Copilot Enterprise.</strong> It allowed an attacker to exfiltrate emails, one-time passwords, password reset links, c…