Security researchers at Varonis Threat Labs report a vulnerability chain affecting Microsoft 365 Copilot Enterprise Search that could enable data exfiltration with a single crafted link. Dubbed “SearchLeak,” the attack combines three bugs into a one-click path that can allow an attacker to obtain sensitive information associated with a target, including emails, calendar details, and indexed files. Sources describe the mechanism as using a specially created URL that points to a legitimate microsoft.com domain. Because the domain appears legitimate, common defenses such as traditional anti-phishing checks and URL filtering may not block the attempt. Bleeping Computer and TechRadar state that the risk could extend to mailbox data as well as data stored in or accessed through OneDrive and SharePoint, depending on how the service is used. The Hacker News and The Next Web emphasize the role of Enterprise Search and the ability to retrieve content through Copilot-linked search features. The reporting collectively urges users and administrators to patch or apply mitigations, but the exact remediation steps are not specified in the excerpts.
Researchers detail one-click theft risk in Microsoft 365 Copilot Enterprise Search
Security researchers at Varonis Threat Labs report a vulnerability chain affecting Microsoft 365 Copilot Enterprise Search that could enable data exfiltration with a single crafted link. Dubbed “Searc...
- Varonis Threat Labs discloses a vulnerability chain in Microsoft 365 Copilot Enterprise Search called “SearchLeak.”
- The chain can enable data exfiltration with a single click using a crafted link.
- The attack can access emails and calendar information, and may also retrieve indexed files.
- The malicious link uses a legitimate microsoft.com domain, potentially bypassing basic URL filtering and anti-phishing tools.
- Researchers describe the exploit as combining three bugs into one attack path and recommend patching or mitigation.
Varonis found a way to chain three bugs into one exploit that can lead to data exfiltration.
2 months agoSecurity researchers at Varonis Threat Labs have disclosed a vulnerability chain in Microsoft 365 Copilot Enterprise Search that could have let an attacker steal emails, calendar entries, and indexed files with a single click. The attack, which Varonis calls SearchLeak, worked through a crafted URL on a legitimate microsoft.com domain, meaning traditional anti-phishing and URL […] This story continues at The Next Web
2 months agoA single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
2 months agoA critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]
2 months ago
Sokoto Hisbah denies imposing restrictions on Christian worship
Sokoto State Hisbah Board rejects claims circulating online that it imposes restrictions on Christian worship and religi...
Kaziah Liz Mejo crowned Miss Universe India 2026 as Sushmita Sen backstage clip sparks debate
Kaziah Liz Mejo is crowned Miss Universe India 2026 in Jaipur, following a competition with 52 national finalists. The 1...
Man who dropped out of college sells Pokémon cards, reports $7.8 million in sales
A man who says he drops out of college to sell Pokémon cards full time reports that his business generated $7.8 million...