Microsoft 365 Copilot can be turned into a one-click data theft tool — inbox, OneDrive, and SharePoint data all at…

https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-2122-80.jpg
  • Varonis uncovered “SearchLeak,” chaining three flaws in Microsoft 365 Copilot to enable one‑click data theft
  • Attack exploited prompt injection, HTML race condition, and Bing SSRF to exfiltrate inbox, OneDrive, and SharePoint data
  • Microsoft patched CVE‑2026‑42824 earlier this month, rating it 10/10 critical

Experts have uncovered a way to turn Microsoft 365 Copilot into a one-click data theft tool, capable of exfiltrating sensitive information from people’s inbox, OneDrive, and SharePoint instances.

The method was recently patched by Microsoft having been developed by security researchers Varonis, who dubbed the method SearchLeak, explaining it works by chaining together three vulnerabilities.

Separately, these three can’t do much harm, but together, they are strong enough to warrant a patch.

Exfiltration proxy

The three flaws being chained are a parameter-to-prompt injection, an HTML rendering race condition, and a content-security-policy (CSP) bypass enabled by Bing server-side request forgery (SSRF).

The attack starts when a victim clicks a...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://cdn.i-scmp.com/sites/default/files/styles/og_image_scmp_generic/public/d8/images/canvas/2026/06/28/cf9b3658-b504-43ba-bcd2-818ba656ac2b_ffb039d5.jpg?itok=vMLDqaUr&v=1782635256

DeepSeek details DSpark, a speculative decoding framework for its V4 models, saying it speeds up AI inference by up to 85% and was tested on Gemma and Qwen

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.