Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Copilot Flaw Allows Data Theft in One Click

Microsoft 365 Copilot Flaw Allows Data Theft in One Click

Posted on June 15, 2026 By CWS

A significant security vulnerability in Microsoft 365 Copilot Enterprise has been identified, allowing attackers to hijack sensitive corporate data, including multifactor authentication codes, email contents, and confidential files. This flaw can be exploited with just one click on a link that appears to be from a legitimate Microsoft domain.

Understanding the SearchLeak Vulnerability

Known as SearchLeak and discovered by Varonis Threat Labs, this vulnerability, tracked as CVE-2026-42824, received the highest severity rating from Microsoft before it was patched. Unlike typical flaws, SearchLeak is a combination of AI-specific and traditional web security issues, turning Microsoft 365 Copilot Enterprise Search into a covert data extraction tool.

SearchLeak is not a singular flaw but a chain of exploits that transforms Microsoft 365 Copilot Enterprise Search into a stealthy exfiltration channel. Varonis researcher Dolev Taler detailed how the attack leverages three separate vulnerabilities: a Parameter-to-Prompt (P2P) Injection, an HTML rendering race condition, and a Server-Side Request Forgery (SSRF) through Bing’s image search.

The Mechanics of the Exploit

Each vulnerability within the chain is manageable on its own, but when combined, they enable a one-click attack that can extract any accessible data from a targeted Microsoft 365 tenant. This does not require special permissions, plugins, or additional actions from the user.

The first stage exploits the P2P Injection, where the q URL parameter in Microsoft 365 Copilot Search is interpreted by the AI engine as executable instructions rather than just a search query. By crafting a malicious URL pointing to a trusted Microsoft domain, attackers can instruct Copilot to extract data and embed it into an image URL.

In the second stage, the attack exploits a race condition bypass. Although Copilot’s output is wrapped in blocks to prevent HTML from rendering, raw HTML is temporarily live in the DOM during the streaming phase. This allows the attacker’s injected tags to execute before sanitization occurs.

Server-Side Request Forgery Exploit

In the final stage, Bing’s image search feature, which accepts an imgurl parameter, is used. As Bing is CSP-allowlisted, it unknowingly fetches and relays stolen data to the attacker’s server, circumventing the Content Security Policy entirely.

This sophisticated attack takes just one click on a crafted link sent through various communication channels. Once clicked, Copilot silently retrieves the victim’s data, embeds it in a Bing image URL, and transfers it to the attacker’s server instantly.

Mitigation and Future Implications

Microsoft has addressed the SearchLeak vulnerability on the server-side, requiring no action from users to receive the patch. However, Varonis advises security teams to monitor Copilot Search URLs for encoded payloads and audit CSP allowlists for domains that perform server-side fetches on user-supplied URLs.

These findings highlight the evolving threat landscape as AI tools introduce new vulnerabilities by reactivating old, previously safe weaknesses. It is crucial for organizations to adapt to these changes and ensure robust security measures.

Cyber Security News Tags:AI security, AI vulnerability, Copilot vulnerability, CVE-2026-42824, Cybersecurity, data security, data theft, HTML race condition, Microsoft 365, parameter-to-prompt injection, SearchLeak, security flaw, server-side request forgery, Varonis Threat Labs, web security

Post navigation

Previous Post: North Korean Hackers Exploit Developer Tools for Cyber Attacks
Next Post: Chinese Cyber Group Exploits Google Workspace to Steal Emails

Related Posts

Underground Ransomware Gang With New Tactics Against Organizations Worldwide Underground Ransomware Gang With New Tactics Against Organizations Worldwide Cyber Security News
GitLab Urges Immediate Update to Fix Security Flaws GitLab Urges Immediate Update to Fix Security Flaws Cyber Security News
PureHVNC RAT Developers Leverage GitHub Host Source Code PureHVNC RAT Developers Leverage GitHub Host Source Code Cyber Security News
Nx Console Extension Breach: Developer Secrets at Risk Nx Console Extension Breach: Developer Secrets at Risk Cyber Security News
GhostSocks Malware Transforms Devices into Proxy Nodes GhostSocks Malware Transforms Devices into Proxy Nodes Cyber Security News
17,000+ VMware ESXi Servers Vulnerable to Critical Integer-Overflow Vulnerability 17,000+ VMware ESXi Servers Vulnerable to Critical Integer-Overflow Vulnerability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Warns Water Sector of Rising Cyber Threats
  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Warns Water Sector of Rising Cyber Threats
  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark