Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

SearchLeak vulnerability allows data theft from Microsoft 365 Copilot Enterprise

The SearchLeak vulnerability (CVE-2026-42824, CVSS 6.5) in Microsoft 365 Copilot Enterprise is a multi-stage attack chain where a victim clicking a malicious URL triggers a parameter injection, leading Copilot to search for sensitive data which is then exfiltrated via an HTML race condition and a CSP bypass using Bing's SSRF. Microsoft has addressed the vulnerability, and no user action is required for mitigation.
Read Full Article →

AI/ML SearchLeak vulnerability allows data theft from Microsoft 365 Copilot Enterprise June 15, 2026 Share By SC Staff (Adobe Stock) Bleeping Computer reports that a critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. The SearchLeak vulnerability, identified as CVE-2026-42824, is a three-stage attack chain developed by Varonis researchers. It combines a parameter-to-prompt injection, an HTML rendering race condition, and a content-security-policy bypass enabled by Bing server-side request forgery (SSRF). The attack begins when a victim clicks a malicious URL. This URL instructs Copilot to search for specific data, such as email content or document titles. During the response streaming, an HTML rendering race condition allows an attacker-controlled image tag to execute, embedding the exfiltrated data within an image URL. This URL is then sent to Bing's "Search by Image" feature, which bypasses CSP protections and fetches the data from the attacker's endpoint. The stolen information is then visible in the attacker's server logs. Microsoft has addressed this critical vulnerability, and no user action is required for mitigation. Source: Bleeping Computer An In-Depth Guide to AI Get essential knowledge and practical strategies to use AI to better your security program. Learn More SC Staff Related Exposure management Securing the model: Protecting AI systems from compromise Paul Wagenseil June 15, 2026 Here's how exposure management offers a practical framework for securing AI. AI/ML AI agents have broken the security perimeter David Mytton June 12, 2026 The successful companies will build security into the workflows where the agents live. AI/ML AI agents are already exploring your network. How do you detect their intent? Harshad Sadashiv Kadam June 11, 2026 AI agents and MCP tools are creating new cybersecurity risks and blind spots. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article