SearchLeak: One Click on Microsoft 365 Copilot Exposes Emails and Files
Researchers at Varonis Threat Labs discovered a chain of vulnerabilities in Microsoft 365 Copilot Enterprise Search that allowed exfiltration of emails, calendars, and indexed files with a single click. The attack, dubbed SearchLeak, leveraged a malicious link on a legitimate Microsoft domain, bypassing traditional anti-phishing filters.



