Security researchers at Varonis Threat Labs report a vulnerability chain affecting Microsoft 365 Copilot Enterprise Search that could enable data exfiltration with a single crafted link. Dubbed “SearchLeak,” the attack combines three bugs into a one-click path that can allow an attacker to obtain sensitive information associated with a target, including emails, calendar details, and indexed files. Sources describe the mechanism as using a specially created URL that points to a legitimate microsoft.com domain. Because the domain appears legitimate, common defenses such as traditional anti-phishing checks and URL filtering may not block the attempt. Bleeping Computer and TechRadar state that the risk could extend to mailbox data as well as data stored in or accessed through OneDrive and SharePoint, depending on how the service is used. The Hacker News and The Next Web emphasize the role of Enterprise Search and the ability to retrieve content through Copilot-linked search features. The reporting collectively urges users and administrators to patch or apply mitigations, but the exact remediation steps are not specified in the excerpts.