Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Copilot Flaw Allows Data Theft in One Click

Microsoft 365 Copilot Flaw Allows Data Theft in One Click

Posted on June 15, 2026 By CWS

A significant security vulnerability in Microsoft 365 Copilot Enterprise has been identified, allowing attackers to hijack sensitive corporate data, including multifactor authentication codes, email contents, and confidential files. This flaw can be exploited with just one click on a link that appears to be from a legitimate Microsoft domain.

Understanding the SearchLeak Vulnerability

Known as SearchLeak and discovered by Varonis Threat Labs, this vulnerability, tracked as CVE-2026-42824, received the highest severity rating from Microsoft before it was patched. Unlike typical flaws, SearchLeak is a combination of AI-specific and traditional web security issues, turning Microsoft 365 Copilot Enterprise Search into a covert data extraction tool.

SearchLeak is not a singular flaw but a chain of exploits that transforms Microsoft 365 Copilot Enterprise Search into a stealthy exfiltration channel. Varonis researcher Dolev Taler detailed how the attack leverages three separate vulnerabilities: a Parameter-to-Prompt (P2P) Injection, an HTML rendering race condition, and a Server-Side Request Forgery (SSRF) through Bing’s image search.

The Mechanics of the Exploit

Each vulnerability within the chain is manageable on its own, but when combined, they enable a one-click attack that can extract any accessible data from a targeted Microsoft 365 tenant. This does not require special permissions, plugins, or additional actions from the user.

The first stage exploits the P2P Injection, where the q URL parameter in Microsoft 365 Copilot Search is interpreted by the AI engine as executable instructions rather than just a search query. By crafting a malicious URL pointing to a trusted Microsoft domain, attackers can instruct Copilot to extract data and embed it into an image URL.

In the second stage, the attack exploits a race condition bypass. Although Copilot’s output is wrapped in blocks to prevent HTML from rendering, raw HTML is temporarily live in the DOM during the streaming phase. This allows the attacker’s injected tags to execute before sanitization occurs.

Server-Side Request Forgery Exploit

In the final stage, Bing’s image search feature, which accepts an imgurl parameter, is used. As Bing is CSP-allowlisted, it unknowingly fetches and relays stolen data to the attacker’s server, circumventing the Content Security Policy entirely.

This sophisticated attack takes just one click on a crafted link sent through various communication channels. Once clicked, Copilot silently retrieves the victim’s data, embeds it in a Bing image URL, and transfers it to the attacker’s server instantly.

Mitigation and Future Implications

Microsoft has addressed the SearchLeak vulnerability on the server-side, requiring no action from users to receive the patch. However, Varonis advises security teams to monitor Copilot Search URLs for encoded payloads and audit CSP allowlists for domains that perform server-side fetches on user-supplied URLs.

These findings highlight the evolving threat landscape as AI tools introduce new vulnerabilities by reactivating old, previously safe weaknesses. It is crucial for organizations to adapt to these changes and ensure robust security measures.

Cyber Security News Tags:AI security, AI vulnerability, Copilot vulnerability, CVE-2026-42824, Cybersecurity, data security, data theft, HTML race condition, Microsoft 365, parameter-to-prompt injection, SearchLeak, security flaw, server-side request forgery, Varonis Threat Labs, web security

Post navigation

Previous Post: North Korean Hackers Exploit Developer Tools for Cyber Attacks
Next Post: Chinese Cyber Group Exploits Google Workspace to Steal Emails

Related Posts

Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers Cyber Security News
Critical Vulnerability in Android Microsoft Teams Exposed Critical Vulnerability in Android Microsoft Teams Exposed Cyber Security News
NAKIVO v11.2 Enhances Replication and vSphere Support NAKIVO v11.2 Enhances Replication and vSphere Support Cyber Security News
Bridgestone Confirms Cyberattack Impacts Manufacturing Facilities Bridgestone Confirms Cyberattack Impacts Manufacturing Facilities Cyber Security News
Jira Software Vulnerability Let Attacker Modify Any Filesystem Path Writable By JVM process Jira Software Vulnerability Let Attacker Modify Any Filesystem Path Writable By JVM process Cyber Security News
GhostClaw Malware Targets macOS Users with AI Tools GhostClaw Malware Targets macOS Users with AI Tools Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks
  • Anthropic Enhances Privacy Policy with Verification Measures

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NarwhalRAT Malware Targets Korean Users via LNK Files
  • Chinese Cyber Group Exploits Google Workspace to Steal Emails
  • Microsoft 365 Copilot Flaw Allows Data Theft in One Click
  • North Korean Hackers Exploit Developer Tools for Cyber Attacks
  • Anthropic Enhances Privacy Policy with Verification Measures

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark