Geometric security barriers breached by AI phishing and data theft.

Daily Cybersecurity News - June 15, 2026

New Attack Turned Microsoft 365 Copilot Into 1 Click Data Theft Tool

A new attack chain turns Microsoft 365 Copilot into a one-click data theft tool that pulls files from mailboxes, OneDrive, and SharePoint.

The SearchLeak chain lets attackers craft a single malicious URL that tricks Copilot into leaking sensitive data. It works without needing credentials once the target clicks.

Any organization running Copilot Enterprise is exposed. The issue hits users who have access to email and file storage in Microsoft 365.

Researchers demonstrated the full chain using just one specially crafted link in testing.

Palo Alto Warns of Active Exploitation of PAN OS GlobalProtect VPN Flaw

Palo Alto just warned that attackers are already abusing an auth bypass in PAN OS GlobalProtect portals to gain unauthorized access.

CVE-2026-0257 scores CVSS 7.8 and lets remote users skip authentication entirely. The flaw is actively exploited by an unknown actor targeting VPN portals.

Only affects deployments with the non-default "authentication override" feature enabled and a specific shared-certificate setup, not every PAN-OS gateway.

Public PoC was published four days after the initial advisory.

Chinese Hackers Breach REDCap Servers Steal Medical Research

Chinese hackers hit exposed REDCap servers at a North American medical institution and stole medical research data.

They deployed InfiniteRed malware on the servers to grab the files. The campaign focused on internet-facing instances running the popular research data platform.

Targeting research environments shows the attackers wanted raw datasets rather than typical patient records. Exposed servers made the entry point straightforward.

Google notified multiple US and Canadian organizations hit in the same campaign. GTIG tracks the actor as UNC6508.

WordPress Plugins Tampered With Hidden Backdoors

An attacker tampered with JavaScript files from three popular WordPress plugins to drop hidden admin accounts on sites.

The scripts from PushEngage, OptinMonster, and TrustPulse were modified so that when an admin viewed the page the code quietly created a new privileged user controlled by the attacker.

This supply-chain style compromise targets the plugin scripts themselves rather than individual site vulnerabilities. It reuses the classic trick of waiting for an authenticated admin to load a page.

Security firm Sansec caught it on June 13, spotting the same malicious code served from Awesome Motive's CDN for all three plugins.

FBI Disrupts Massive AI Powered Phishing Service

FBI took down a large Chinese phishing service called Outsider Enterprise that used AI to spin up phishing sites at scale.

They worked with Google and Black Lotus Labs to seize over a million URLs tied to credit card and password theft. Thousands of active phishing domains got pulled offline in the process.

This hits the infrastructure hard for now, but the operators remain in China where arrests rarely follow these operations.

Same service ran for years before this hit, expect quick rebuilds using different domains.