SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
CYBERSECURITY FEATURED ANALYSIS

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

SOURCE

Cloud Security Alliance

DATE

READ

1 min read

Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private …

Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon. Dubbed SearchLeak, the chain combines a relatively new class