Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Copilot Security Issue Risks Email Privacy

Microsoft 365 Copilot Security Issue Risks Email Privacy

Posted on February 18, 2026 By CWS

A recent security flaw in Microsoft 365 Copilot is raising concerns over email privacy. The AI assistant is reportedly bypassing confidentiality sensitivity labels, leading to unauthorized summarization of potentially sensitive emails. This issue poses a significant risk to data protection within organizations.

Details of the Identified Flaw

First reported on February 4, 2026, and tracked under reference CW1226324, the flaw allows Microsoft 365 Copilot’s ‘Work Tab’ Chat feature to summarize emails labeled as confidential. These actions occur despite the presence of Data Loss Prevention (DLP) policies designed to restrict such processing.

Microsoft’s investigation revealed the root cause to be a code-level defect. This defect mistakenly allows the AI to access emails stored in the Sent Items and Draft folders, effectively bypassing the confidentiality labels intended to protect these messages.

Impact on Regulated Industries

The flaw is particularly concerning for sectors such as healthcare, finance, and government, where stringent email confidentiality is not just a best practice but a regulatory requirement. The National Health Service (NHS) has internally flagged the issue as INC46740412, highlighting its potential impact on public sector users of Microsoft 365.

Microsoft has started deploying a fix as of February 11, 2026, targeting affected environments. However, the resolution process is ongoing, and the issue remains unresolved for some users. Organizations are advised to monitor updates and review Copilot activity logs for any unusual access to labeled content.

Ensuring Data Security and Compliance

The bypassing of DLP policies by an AI tool like Copilot highlights a critical security gap. These controls are essential for data governance, and their circumvention can undermine an organization’s information protection strategy. Until a full resolution is achieved, organizations handling highly sensitive communications might consider temporarily limiting Copilot’s access.

Microsoft anticipates releasing further updates by February 18, 2026, with the aim of providing a comprehensive remediation timeline as the situation evolves.

Stay informed by following us on Google News, LinkedIn, and X for the latest cybersecurity updates. Contact us for further insights or to share your stories.

Cyber Security News Tags:AI security, Compliance, Copilot flaw, cybersecurity updates, data protection, DLP policies, email privacy, enterprise security, Microsoft 365, sensitivity labels

Post navigation

Previous Post: Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises
Next Post: Microsoft Exchange Error Flags Legitimate Emails as Phishing

Related Posts

Pune Auto Parts Firm Loses ₹2.35 Crore in Man-in-the-Middle Attack Pune Auto Parts Firm Loses ₹2.35 Crore in Man-in-the-Middle Attack Cyber Security News
Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets Cyber Security News
Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto Cyber Security News
New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data New ModStealer Evade Antivirus Detection to Attack macOS Users and Steal Sensitive Data Cyber Security News
Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program Cyber Security News
Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Exchange Error Flags Legitimate Emails as Phishing
  • Microsoft 365 Copilot Security Issue Risks Email Privacy
  • Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises
  • Ivanti EPMM Vulnerabilities Threaten Global Networks
  • Crypto Scams Surge in Asia with Sophisticated Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Exchange Error Flags Legitimate Emails as Phishing
  • Microsoft 365 Copilot Security Issue Risks Email Privacy
  • Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises
  • Ivanti EPMM Vulnerabilities Threaten Global Networks
  • Crypto Scams Surge in Asia with Sophisticated Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News