One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Varonis chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfiltration path — emails, files, and MFA codes were reachable via a trusted Microsoft URL.
Summary written by editorial AI · Source link below
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search.
Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
Editorial Analysis
AI-powered enterprise search surfaces sensitive data from across tenants; chained flaws in these tools create high-impact exfiltration paths that bypass users' security instincts.
Review Copilot Enterprise Search permissions, restrict indexed content scope, and monitor for anomalous search-API calls.
A vulnerability chain in Microsoft's AI search assistant could have exposed corporate emails and MFA codes through a single trusted link.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the AI Security Desk
- Hugging Face warns an autonomous AI agent hacked its network20 Jul
- Jailbreak Foundry: From Papers to Runnable Attacks for Reproducible Benchmarking20 Jul
- Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior20 Jul
- Poison to Detect: Detection of Targeted Overfitting in Federated Learning20 Jul
- Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation20 Jul