Back Feeds.4Sysops Microsoft patches SearchLeak vulnerability in Copilot for Microsoft 365
Microsoft has addressed a critical vulnerability chain in Copilot for Microsoft 365 that allowed for unauthorized data exfiltration. The flaw, identified as CVE-2026-42824 and dubbed SearchLeak, enabled attackers to steal sensitive information from a user's mailbox, OneDrive, and SharePoint. Because the fix was implemented on the backend, organizations do not need to take any manual action to protect their environments. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
