WorkThe story, in brief

New attack turned Microsoft 365 Copilot into 1-click data theft tool - BleepingComputer

Microsoft 365 Copilot had a critical flaw that could steal emails, files, and MFA codes in one click. Here's what just got patched.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

A major security vulnerability in Microsoft 365 Copilot exposed enterprise data to one-click theft attacks. This highlights the growing security risks embedded in AI-integrated productivity tools that handle sensitive corporate information—a critical concern for enterprise leaders deploying Copilot at scale.

The key facts

5 to know
  1. Vulnerability: One-click data theft attack vector in Microsoft 365 Copilot

  2. Data at risk: Emails, files, and MFA codes

  3. Severity: Critical (patched by Microsoft)

  4. Flaw name: SearchLeak

  5. Impact scope: Microsoft 365 Copilot users

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: New attack turned Microsoft 365 Copilot into 1-click data theft tool BleepingComputer One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes The Hacker News Microsoft Patches Critical SearchLeak Flaw in 365 Copilot The420.in
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work