VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_c87e9ab186a4fe66e67bd98d34f03945

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Published Jun 15, 2026

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search.

Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were

Affected AI Products

copilot
Get the weekly digest. Every Monday: top AI security stories of the week. Free.