search

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

source Source: Cloud Security Alliance
calendar_today
schedule 1 min read

Varonis Threat Labs has identified a significant vulnerability known as SearchLeak in Microsoft 365 Copilot Enterprise. This multi-stage vulnerability allows attackers to easily access and steal sensitive information, including MFA codes, emails, meeting details, and confidential organizational files, with just one click. The discovery highlights serious security risks associated with Microsoft 365 Copilot, which can be exploited for silent data exfiltration.

Related articles

cybersecurity

New North Korean campaign uses fake coding interviews to steal developer credentials

DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.

cybersecurity

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.

cybersecurity

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.