New Attack Turned Microsoft 365 Copilot Into 1 Click Data Theft Tool
A new attack chain turns Microsoft 365 Copilot into a one-click data theft tool that pulls files from mailboxes, OneDrive, and SharePoint.
The SearchLeak chain lets attackers craft a single malicious URL that tricks Copilot into leaking sensitive data. It works without needing credentials once the target clicks.
Any organization running Copilot Enterprise is exposed. The issue hits users who have access to email and file storage in Microsoft 365.
Researchers demonstrated the full chain using just one specially crafted link in testing.
