FeedData BreachNew attack turned Microsoft 365 Copilot into 1-click data th...
Data BreachBleeping Computer
7.5HIGH

New attack turned Microsoft 365 Copilot into 1-click data theft tool

📅 15 June 2026 at 13:00 UTC📰 Bleeping ComputerView original source ↗
New attack turned Microsoft 365 Copilot into 1-click data theft tool

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise allows attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. The attack exploits three flaws: parameter-to-prompt injection, HTML rendering race condition, and content-security-policy bypass enabled by Bing server-side request forgery.

⚙️Technical Details
CVEs
CVE-2026-42824
Affected Systems
Microsoft Copilot
Attack Vectors
NETWORK
💥Impact Assessment
Severity: critical
Who Is at Risk
Users with Microsoft 365 Copilot Enterprise, particularly those in sensitive sectors such as finance and government.
🛡️Recommended Actions
1Implement a web application firewall (WAF) to block malicious traffic.
2Regularly update and patch Microsoft 365 Copilot Enterprise with the latest security patches.
3Monitor user activity and system logs for suspicious behavior.
📦Affected Products
Microsoft Copilot
🔐NVD Verified DataVERIFIED
CVE-2026-42824CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-77
Affected Products (CPE)
Microsoft Copilot

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed