Signal

SearchLeak vulnerability enables one-click data theft from Microsoft 365 Copilot Enterprise

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-15 13:00 UTCUpdated 2026-06-15 22:53 UTC
rss
cveexploitssecurity_toolingincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

A critical vulnerability chain named SearchLeak (CVE-2026-42824) affects Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data including emails, calendar details, files, and MFA codes via a specially crafted URL.

Entities
MicrosoftVaronis Threat LabsMicrosoft 365 Copilot
Score total
1.33
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • The vulnerability was recently discovered and publicly disclosed, requiring immediate attention.
  • Attackers could exploit this flaw with minimal user interaction—a single click.
  • Organizations using Microsoft 365 Copilot Enterprise need to assess and mitigate this risk promptly.
Why it matters
  • The vulnerability enables attackers to bypass traditional anti-phishing defenses using legitimate microsoft.com URLs.
  • It exposes sensitive enterprise data including emails, files, and MFA codes, risking data breaches.
  • Highlights security risks in AI-powered enterprise tools like Microsoft 365 Copilot.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • SearchLeak vulnerability allows attackers to steal emails, files, calendar details, and MFA codes from Microsoft 365 Copilot Enterprise via a one-click attack.
How sources frame it
  • BleepingComputer: neutral
Consolidated multiple reports into a clear narrative emphasizing the criticality and unique bypass method of the SearchLeak vulnerability.
All evidence
All evidence
New attack turned Microsoft 365 Copilot into 1-click data theft tool
bleepingcomputer_all · bleepingcomputer.com · 2026-06-15 13:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
  • SC Media (1)
  • thehackernews (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • scworld.com (1)
  • thehackernews.com (1)
  • bleepingcomputer.com (1)