threat-intel Copilot 'SearchLeak' Attack Allows 1-Click Data Theft A critical vulnerability, dubbed ‘SearchLeak,’ has been discovered in Microsoft Copilot that allows attackers to silently steal user data through a novel prompt injection technique. The attack leverages a race condition involving Bing search-by-image to bypass Copilot’s guardrails and extract sensitive information like… Dark Reading · Jun 15, 2026 Critical CVE-2026-42824prompt injectionai securitymicrosoft copilot
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel New attack turned Microsoft 365 Copilot into 1-click data theft tool A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially craf… BleepingComputer · Jun 15, 2026 Critical CVE-2026-42824prompt injectionssrfhtml injection
vulnerability Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft released its June 2026 security patch update, addressing 206 vulnerabilities across its product suite. A significant portion, 32 critical vulnerabilities, focus on remote code execution (RCE) issues within prod… Cisco Talos · Jun 9, 2026 High CVE-2026-42985CVE-2026-47291CVE-2026-44803remote code executionbuffer overflowinteger overflow