Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Copilot Security Issue Risks Email Privacy

Microsoft 365 Copilot Security Issue Risks Email Privacy

Posted on February 18, 2026 By CWS

A recent security flaw in Microsoft 365 Copilot is raising concerns over email privacy. The AI assistant is reportedly bypassing confidentiality sensitivity labels, leading to unauthorized summarization of potentially sensitive emails. This issue poses a significant risk to data protection within organizations.

Details of the Identified Flaw

First reported on February 4, 2026, and tracked under reference CW1226324, the flaw allows Microsoft 365 Copilot’s ‘Work Tab’ Chat feature to summarize emails labeled as confidential. These actions occur despite the presence of Data Loss Prevention (DLP) policies designed to restrict such processing.

Microsoft’s investigation revealed the root cause to be a code-level defect. This defect mistakenly allows the AI to access emails stored in the Sent Items and Draft folders, effectively bypassing the confidentiality labels intended to protect these messages.

Impact on Regulated Industries

The flaw is particularly concerning for sectors such as healthcare, finance, and government, where stringent email confidentiality is not just a best practice but a regulatory requirement. The National Health Service (NHS) has internally flagged the issue as INC46740412, highlighting its potential impact on public sector users of Microsoft 365.

Microsoft has started deploying a fix as of February 11, 2026, targeting affected environments. However, the resolution process is ongoing, and the issue remains unresolved for some users. Organizations are advised to monitor updates and review Copilot activity logs for any unusual access to labeled content.

Ensuring Data Security and Compliance

The bypassing of DLP policies by an AI tool like Copilot highlights a critical security gap. These controls are essential for data governance, and their circumvention can undermine an organization’s information protection strategy. Until a full resolution is achieved, organizations handling highly sensitive communications might consider temporarily limiting Copilot’s access.

Microsoft anticipates releasing further updates by February 18, 2026, with the aim of providing a comprehensive remediation timeline as the situation evolves.

Stay informed by following us on Google News, LinkedIn, and X for the latest cybersecurity updates. Contact us for further insights or to share your stories.

Cyber Security News Tags:AI security, Compliance, Copilot flaw, cybersecurity updates, data protection, DLP policies, email privacy, enterprise security, Microsoft 365, sensitivity labels

Post navigation

Previous Post: Cybersecurity Alert: Fake CAPTCHA Attack Endangers Enterprises
Next Post: Microsoft Exchange Error Flags Legitimate Emails as Phishing

Related Posts

FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks Cyber Security News
Nike Allegedly Hacked by WorldLeaks Ransomware Group Nike Allegedly Hacked by WorldLeaks Ransomware Group Cyber Security News
New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit New Research Uncovers the Alliance Between Qilin, DragonForce and LockBit Cyber Security News
Apple Fixes 0-Day Vulnerabilities in Older version of iPhones and iPad Apple Fixes 0-Day Vulnerabilities in Older version of iPhones and iPad Cyber Security News
AI Crawlers Reshape The Internet With Over 30% of Global Web Traffic AI Crawlers Reshape The Internet With Over 30% of Global Web Traffic Cyber Security News
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Exploit Drift in $285 Million Crypto Heist
  • Fortinet Addresses Critical FortiClient EMS Vulnerability
  • 36 Malicious npm Packages Exploit Databases for Persistent Access
  • Node.js Developers Face Advanced Social Engineering Threat
  • Hackers Exploit Code Leak to Spread Malware via GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Exploit Drift in $285 Million Crypto Heist
  • Fortinet Addresses Critical FortiClient EMS Vulnerability
  • 36 Malicious npm Packages Exploit Databases for Persistent Access
  • Node.js Developers Face Advanced Social Engineering Threat
  • Hackers Exploit Code Leak to Spread Malware via GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark