Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Flaw Risked Email and File Theft

Microsoft 365 Flaw Risked Email and File Theft

Posted on June 15, 2026 By CWS

A vulnerability in Microsoft 365 Copilot exposed a risk where a single click could lead to unauthorized access to emails, calendar data, and files. This flaw was identified by Varonis Threat Labs, who termed the exploit SearchLeak.

SearchLeak involved chaining three vulnerabilities into a seamless attack path, leveraging trusted microsoft.com links, which traditional security tools might not flag. Microsoft has since addressed this issue on their servers, ensuring that users remain protected.

Understanding the Vulnerability

Microsoft’s advisory highlighted the flaw as a command injection risk within their network. This attack combined AI vulnerabilities with existing web bugs, exploiting the q parameter in the Copilot Enterprise Search URL. Originally meant for search queries, this parameter could be manipulated to execute undesired actions.

The flaw allowed attackers to fetch email titles and embed them in image URLs without user interaction beyond an initial click. The attack was facilitated by a race condition in the browser’s rendering process, which allowed malicious requests to execute before security measures could neutralize them.

Exploiting Security Policies

Another critical aspect involved bypassing the Content Security Policy (CSP) of m365.cloud.microsoft. While CSP typically blocks images from untrusted domains, it allows those from *.bing.com. By leveraging Bing’s “Search by Image” feature, attackers could exfiltrate data via Bing’s infrastructure, effectively using it as a proxy.

This method meant that once the victim clicked a malicious link, the information could be extracted and logged by attackers. With access to sensitive items like MFA codes and password reset links, the potential for account takeover was significant.

Previous Incidents and Future Outlook

Varonis had previously exposed a similar vulnerability, Reprompt, which targeted Copilot Personal users. Despite additional security measures for Enterprise users, this pattern persisted, indicating a need for enhanced safeguards.

In response, Microsoft has mitigated the flaw, but ongoing vigilance is advised for enterprise administrators. Monitoring encoded payloads in search URLs and unusual Bing image requests can help detect potential threats.

Enhancing data governance and limiting the scope of Copilot’s indexing can also reduce exposure to future vulnerabilities, ensuring more robust protection of sensitive enterprise data.

The Hacker News Tags:Copilot, CVE-2026-42824, Cybersecurity, data breach, data protection, email security, enterprise security, MFA codes, Microsoft 365, Phishing, SearchLeak, security flaw, SharePoint, Varonis, Vulnerability

Post navigation

Previous Post: Ad Blocker Extensions Secretly Capture AI Chats
Next Post: Hack Targets French Government Messaging Platform

Related Posts

Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks The Hacker News
Malicious Telnyx Versions on PyPI: Audio Steganography Attack Malicious Telnyx Versions on PyPI: Audio Steganography Attack The Hacker News
MuddyWater Intensifies Cyber Attacks in MENA with New Malware MuddyWater Intensifies Cyber Attacks in MENA with New Malware The Hacker News
Global Crackdown Dismantles SocksEscort Proxy Botnet Network Global Crackdown Dismantles SocksEscort Proxy Botnet Network The Hacker News
Zoom Resolves Critical Windows Vulnerability Zoom Resolves Critical Windows Vulnerability The Hacker News
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark