threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The flaw exploited command injection and a race condition, leveraging Bing’s image endpoint to bypass sec… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing