Close Menu
    What's Hot

    Brazil-born Nunes on representing Portugal: ‘I owe more to Portugal’

    2026 U.S. Open odds, picks: Scottie Scheffler, Rory McIlroy predictions by model that nailed 17 majors

    Salesforce acquires AI customer service platform Fin for $3.6 billion

    Facebook X (Twitter) Instagram
    Trending
    • Brazil-born Nunes on representing Portugal: ‘I owe more to Portugal’
    • 2026 U.S. Open odds, picks: Scottie Scheffler, Rory McIlroy predictions by model that nailed 17 majors
    • Salesforce acquires AI customer service platform Fin for $3.6 billion
    • Stanford grads booed Google CEO Sundar Pichai’s commencement speech—but not for the reason you think
    • Lawmakers Warn Trump Officials Not to Pursue Arch Project Without Congress
    • Summer ICE
    • California Governor Newsom says US Department of Justice investigating him | Politics News
    • How Soon Until Oil Prices Come Down?
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

    adminBy adminJune 15, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJun 15, 2026Vulnerability / Enterprise Security

    One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

    A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search.

    Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were unlikely to flag it.

    No prompt, no password, no second click. Microsoft assigned CVE-2026-42824 and marked it critical; the CVSS scores ran lower and disagreed, 6.5 from Microsoft and 7.5 from the National Vulnerability Database. The company mitigated the flaw on its backend, so customers have nothing to worry about, and Varonis presented a proof-of-concept, not observed exploitation.

    Three bugs, one click

    Microsoft’s advisory describes the flaw as a command injection that can expose information over a network. In practice, SearchLeak stacks one AI-specific weakness on two old web bugs, and each link is needed for the next.

    The entry point is the q parameter in the Copilot Enterprise Search URL. It is meant for a natural-language query, but Copilot reads whatever sits there as instructions, not just a search string.

    Varonis calls this Parameter-to-Prompt injection. An attacker writes a URL that tells Copilot to search the mailbox, take an email title, and place it inside an image URL. The victim types nothing. They click, and Copilot does the work.

    Cybersecurity

    Next is a race condition in how the response renders. Microsoft’s guardrail wraps Copilot output in blocks so the browser treats markup as text. The catch is timing: the wrapping happens after Copilot finishes generating, but the browser renders the stream as it arrives. The injected tag is drawn and fires its request before the sanitizer runs. By the time the output is neutralized, the request has already left.

    The last link gets the data past the page’s Content Security Policy. The CSP on m365.cloud.microsoft blocks images from arbitrary domains, but it allowlists *.bing.com. Bing’s “Search by Image” endpoint accepts an image URL and fetches it server-side to analyze it. Point that fetch at an attacker’s server with the stolen text encoded in the path, and Bing retrieves it. The browser’s CSP never applies, because the request comes from Bing’s infrastructure. Bing becomes the exfiltration proxy. The CSP allowlist does the hiding.

    Put together: the victim clicks, Copilot searches their data, the response embeds a value like an email subject in a Bing image URL, the browser calls Bing during streaming, and Bing pulls the attacker’s URL. The attacker reads it off their own logs, for example, a request for /Your_Security_Code_847291/img.png.

    What an attacker gets

    Copilot Enterprise can reach whatever the signed-in user can, through their Microsoft Graph access, and the attacker inherits that reach without ever logging in.

    The most time-sensitive prize sits in the inbox: one-time codes, MFA codes, and password-reset links, often still valid for a few minutes. A script that lifts those off a log while the window is open can take over an account before anyone notices.

    Cybersecurity

    The same access also reaches calendar invites, meeting notes, and any SharePoint or OneDrive file Copilot has indexed, where the salary data, earnings figures, and acquisition plans live.

    SearchLeak is the second time Varonis has shown this pattern. Varonis researcher Dolev Taler demonstrated the same one-click technique in an earlier Reprompt attack against Copilot Personal, and it held up against Enterprise Search despite the extra guardrails that tier is supposed to enforce.

    The same pattern showed up in EchoLeak (CVE-2025-32711), the zero-click Copilot data-leak bug Aim Security disclosed in 2025. SSRF and sanitizer races are old bug classes; the prompt injection is the new part, and it makes them reachable again.

    Microsoft mitigated the flaw on its backend, and because Copilot Enterprise is a managed service, tenant admins cannot patch or reconfigure the parts that failed. What they can do is watch and contain.

    Look for Copilot Search URLs carrying encoded payloads or HTML in the q parameter, and for unusual outbound requests to Bing’s image endpoints. Tighten data-access governance so Copilot indexes less, which shrinks what any future leak can reach.

    Attackers Codes Copilot emails files flaw MFA Microsoft OneClick steal
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleIran Hawks Side-Eye Trump’s Deal
    Next Article Amazon’s Smart Thermostat is on sale for just $58
    admin
    • Website

    Related Posts

    Microsoft weighs an Xbox spinoff. Would it revive the business or put it at risk?

    June 15, 2026

    LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

    June 15, 2026

    Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

    June 15, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Brazil-born Nunes on representing Portugal: ‘I owe more to Portugal’

    2026 U.S. Open odds, picks: Scottie Scheffler, Rory McIlroy predictions by model that nailed 17 majors

    Salesforce acquires AI customer service platform Fin for $3.6 billion

    Stanford grads booed Google CEO Sundar Pichai’s commencement speech—but not for the reason you think

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by