New attack turned Microsoft 365 Copilot into 1-click data theft tool - BleepingComputer
Microsoft 365 Copilot had a critical flaw that could steal emails, files, and MFA codes in one click. Here's what just got patched.

Why it matters
A major security vulnerability in Microsoft 365 Copilot exposed enterprise data to one-click theft attacks. This highlights the growing security risks embedded in AI-integrated productivity tools that handle sensitive corporate information—a critical concern for enterprise leaders deploying Copilot at scale.
The key facts
5 to knowVulnerability: One-click data theft attack vector in Microsoft 365 Copilot
Data at risk: Emails, files, and MFA codes
Severity: Critical (patched by Microsoft)
Flaw name: SearchLeak
Impact scope: Microsoft 365 Copilot users
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: New attack turned Microsoft 365 Copilot into 1-click data theft tool BleepingComputer One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes The Hacker News Microsoft Patches Critical SearchLeak Flaw in 365 Copilot The420.in