news.mlab.sh
Back to the feed
threat-intel

New attack turned Microsoft 365 Copilot into 1-click data theft tool

Critical
Summary

A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially crafted URL. The attack chain exploits prompt injection, HTML rendering race conditions, and a Bing SSRF bypass, enabling data exfiltration without user interaction after Microsoft's patch. This highlights the potential for AI-powered systems to amplify the impact of traditional vulnerabilities.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.