discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

A one-click flaw in Microsoft 365 Copilot could have let attackers steal emails, files, and MFA codes. Researchers at Varonis Threat Labs discovered the flaw, which is now mitigated by Microsoft.

By Swati Khandelwal·Jun 15·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Image: thehackernews.com

The flaw, called SearchLeak, allowed attackers to exfiltrate data from Microsoft 365 Copilot Enterprise Search with a single click on a trusted Microsoft link.

Why it matters

This vulnerability matters because it could have allowed attackers to steal sensitive information, including emails, files, and MFA codes, from Microsoft 365 users. The fact that it was a one-click flaw makes it particularly concerning.

Imagine you're using a search engine to find something on your computer. But instead of just searching, the search engine can also do things on its own, like send emails or open files. That's kind of like what Microsoft 365 Copilot does. But there was a bug that let bad people trick Copilot into sending them secret information, like passwords or private emails. It was like a magic trick, but not a good one.

Analysis

The SearchLeak flaw was discovered by researchers at Varonis Threat Labs, who found that it was possible to chain three bugs together to create a one-click exfiltration path. The first bug was a command injection vulnerability that allowed attackers to inject malicious code into the Copilot Enterprise Search URL. The second bug was a race condition in how the response was rendered, which allowed the injected code to be executed before the sanitizer could neutralize it. The third bug was a Content Security Policy (CSP) bypass, which allowed the attacker to exfiltrate the stolen data to their own server. The attacker could use the stolen data to take over the user's account, access sensitive information, and perform other malicious activities. Microsoft has mitigated the flaw on its backend, but users are still advised to be cautious and monitor their accounts for any suspicious activity. The discovery of this flaw highlights the importance of continuous security testing and monitoring, as well as the need for users to be aware of the potential risks associated with using cloud-based services. The fact that this flaw was discovered in a managed service like Microsoft 365 Copilot Enterprise Search also underscores the need for cloud service providers to prioritize security and ensure that their services are properly secured. The SearchLeak flaw is not an isolated incident, as Varonis researcher Dolev Taler had previously demonstrated a similar one-click technique in an earlier Reprompt attack against Copilot Personal. This pattern of vulnerabilities highlights the need for ongoing security research and testing to identify and mitigate potential flaws before they can be exploited by attackers.

Key points

  • The SearchLeak flaw allowed attackers to exfiltrate data from Microsoft 365 Copilot Enterprise Search with a single click
  • The flaw was caused by a combination of three bugs, including a command injection vulnerability, a race condition, and a CSP bypass
  • Microsoft has mitigated the flaw on its backend, but users are still advised to be cautious and monitor their accounts for any suspicious activity
The Upside

The fact that Microsoft was able to mitigate the flaw on its backend means that users do not need to take any immediate action to protect themselves. Additionally, the discovery of this flaw highlights the importance of continuous security testing and monitoring, which can help to identify and mitigate potential vulnerabilities before they can be exploited. As cloud service providers continue to prioritize security, users can expect to see improved protections and safeguards in place to prevent similar vulnerabilities from being exploited in the future.

The Downside

The discovery of the SearchLeak flaw highlights the potential risks associated with using cloud-based services, particularly those that have access to sensitive information. The fact that this flaw was able to be exploited with a single click makes it particularly concerning, as it could have allowed attackers to steal sensitive information from Microsoft 365 users. If similar vulnerabilities are discovered in the future, it could have serious consequences for users and organizations that rely on cloud-based services.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymicrosoftcloud-computingvulnerabilityenterprise-security

Author

Swati Khandelwal

Intelligence analysis by

Llama 3.3 70B

Published

Jun 15, 2026

Source

thehackernews.com

Share

Topics

securitymicrosoftcloud-computingvulnerabilityenterprise-security

Related

More from this desk

Aug 20·bleepingcomputer.com

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

Aug 20·bleepingcomputer.com

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability. This vulnerability can be used by attackers without privileges to remotely access internal services or cloud metadata…

Aug 20·thehackernews.com

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrumen…

Aug 20·bleepingcomputer.com

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targets users in multiple European countries, combining spyware, banking fraud, and remote control capabilities. It captures user taps, intercepts notifications and SMS messages, collects files and location data, and provides remote contr…