Critical SearchLeak Vulnerability in Microsoft 365 Copilot Allows One-Click Data Theft

A critical vulnerability chain, named SearchLeak (CVE-2026-42824), was discovered in Microsoft 365 Copilot Enterprise, allowing attackers to exfiltrate sensitive data with a single click on a crafted URL. The attack expl…

Free daily limit reached

Create a free account to keep reading

Unlimited cluster & entity views, full AI analysis, threat scoring, entities, sources and timelines — free, no card required.

Sign up free

Already have an account? Log in