PulseAugur
EN
LIVE 21:33:07

Critical "SearchLeak" vulnerability in Microsoft 365 Copilot allows data exfiltration

A critical vulnerability dubbed "SearchLeak" has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to exfiltrate sensitive data with a single click. The vulnerability chain, identified by Varonis Threat Labs, exploits three distinct weaknesses to gain access to emails, passwords, and indexed organizational files. Microsoft has since patched the backend vulnerability and disclosed it with a critical severity rating, noting that no administrator action is required for the fix. AI

IMPACT Exposes enterprise AI assistants to prompt injection risks, highlighting the need for robust security measures in AI integrations.

RANK_REASON Discovery of a specific vulnerability in a widely used enterprise AI product.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Critical "SearchLeak" vulnerability in Microsoft 365 Copilot allows data exfiltration

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Logan ·

    CVE-2026-42824 SearchLeak: How M365 Copilot Became a One-Click Data Exfiltration Tool

    <p><strong>CVE-2026-42824, named "SearchLeak" by Varonis Threat Labs researchers who discovered it, is a critical three-stage vulnerability chain in Microsoft 365 Copilot Enterprise.</strong> It allowed an attacker to exfiltrate emails, one-time passwords, password reset links, c…