Breaking
BreakingSlashdotFrance to Cease Certifying Products Without Quantum-Resistant Encryption· 2 minutes agoBreakingMashable TechMicrosoft Copilot 'SearchLeak' Vulnerability Exposes Sensitive Enterprise Data· 2 minutes agoBreaking9to5MacWhatsApp Develops New Ephemeral Messaging Feature for iOS· 2 minutes agoBreakingBuenos Aires TimesÁngel Di María Absent from World Cup for First Time in 16 Years, Backs Argentina· 2 minutes agoBreakingChannel News AsiaCommentary Explores Cultural Significance of World Cup Chants· 2 minutes agoBreakingFrance 24France Secures 3-1 Victory Against Senegal in World Cup 2026 Opener· 2 minutes agoBreakingHollywood ReporterBruce Springsteen Dedicates Social Justice Award, Discusses Activism with Bono· 2 minutes agoBreakingBBC SportMbappe Scores Twice as France Defeats Senegal in World Cup Opener· 2 minutes agoBreakingGlobe and MailUK Military Investigates Russian Warship Warning Shots Near Yacht in Channel· 7 minutes agoBreakingSydney Morning HeraldFBI Alleges Thwarted Plot Against White House UFC Event· 7 minutes agoBreakingSlashdotFrance to Cease Certifying Products Without Quantum-Resistant Encryption· 2 minutes agoBreakingMashable TechMicrosoft Copilot 'SearchLeak' Vulnerability Exposes Sensitive Enterprise Data· 2 minutes agoBreaking9to5MacWhatsApp Develops New Ephemeral Messaging Feature for iOS· 2 minutes agoBreakingBuenos Aires TimesÁngel Di María Absent from World Cup for First Time in 16 Years, Backs Argentina· 2 minutes agoBreakingChannel News AsiaCommentary Explores Cultural Significance of World Cup Chants· 2 minutes agoBreakingFrance 24France Secures 3-1 Victory Against Senegal in World Cup 2026 Opener· 2 minutes agoBreakingHollywood ReporterBruce Springsteen Dedicates Social Justice Award, Discusses Activism with Bono· 2 minutes agoBreakingBBC SportMbappe Scores Twice as France Defeats Senegal in World Cup Opener· 2 minutes agoBreakingGlobe and MailUK Military Investigates Russian Warship Warning Shots Near Yacht in Channel· 7 minutes agoBreakingSydney Morning HeraldFBI Alleges Thwarted Plot Against White House UFC Event· 7 minutes ago
Technology
Source: Mashable Tech

Microsoft Copilot 'SearchLeak' Vulnerability Exposes Sensitive Enterprise Data

Cybersecurity researchers at Varonis Threat Labs have uncovered a new three-stage vulnerability chain, named 'SearchLeak,' affecting Microsoft 365 Copilot Enterprise Search. This exploit reportedly enables attackers to access and exfiltrate sensitive information, including emails, two-factor authentication codes, and various indexed business content. The vulnerability works by combining a novel AI-specific injection with existing web bugs, effectively circumventing Copilot's built-in data protection mechanisms.

By Fainaron·Jun 16, 2026 (2 minutes ago)·1 views
Microsoft Copilot 'SearchLeak' Vulnerability Exposes Sensitive Enterprise Data

A new vulnerability dubbed 'SearchLeak' has been identified in Microsoft 365 Copilot Enterprise Search by cybersecurity researchers at Varonis Threat Labs. The vulnerability chain is described as a method to turn the AI assistant into a "silent data exfiltration weapon."

'SearchLeak' is a three-stage attack that could expose a range of sensitive data, including emails, two-factor authentication codes, meeting invites, notes, SharePoint documents, and OneDrive files. The researchers indicate that the 'blast radius' extends beyond personal data within the enterprise environment, potentially covering any content the user has access to within an organization.

The attack begins with a Parameter-to-Prompt Injection (P2P), an AI-specific vulnerability. An attacker sends a target a URL containing a malicious prompt as a query parameter. When the target clicks this link, Copilot interprets the embedded prompt as instructions, such as searching for emails and embedding their titles into an image URL.

The second stage involves an HTML injection race condition. According to Varonis, a flaw in Copilot's rendering process allows raw HTML to be temporarily displayed in the Document Object Model (DOM) during the streaming phase, before Microsoft's protective formatting is applied.

Finally, to retrieve the exposed information, the attack utilizes a Content Security Policy (CSP) bypass through Bing server-side request forgery (SSRF). The malicious prompt directs Copilot to use an attacker-controlled domain as the image URL destination, leveraging Bing's Search by Image feature as a proxy to circumvent restrictions on external image domains.

Microsoft has implemented safety guardrails in Copilot designed to prevent data exfiltration. However, the 'SearchLeak' vulnerability reportedly operates as a combined three-stage chain, allowing it to bypass these safeguards, whereas individual components of the attack would likely fail on their own. According to Mashable Tech, this mechanism effectively works around Microsoft's built-in protections.

Source attribution: This article was AI-curated and rewritten by Fainaron from a piece originally published by Mashable Tech. Read the original at Mashable Tech →

More like this

Binance Faces Potential EU Operating Ban Following Reported Greek MiCA License Rejection
Technology
2 minutes ago

Binance Faces Potential EU Operating Ban Following Reported Greek MiCA License Rejection

Binance, a global cryptocurrency exchange, is reportedly set to lose its permission to serve customers within the European Union starting in July. This development stems from a reported decision by Greek regulators to reject the company's application for a Markets in Crypto-Assets (MiCA) license. Under new EU rules, crypto firms must secure a MiCA license by the end of June to operate across the 27-nation bloc, with a rejection from one member state potentially preventing wider EU operations. Binance, which states it has 300 million customers worldwide, maintains it has diligently pursued the license and believes its application was compliant.

Slashdot
Z.ai Releases Open-Weights GLM-5.2 LLM, Outperforms GPT-5.5 in Coding Benchmarks
Technology
2 minutes ago

Z.ai Releases Open-Weights GLM-5.2 LLM, Outperforms GPT-5.5 in Coding Benchmarks

Chinese AI startup Z.ai has launched GLM-5.2, a 753-billion parameter open-weights large language model (LLM) designed for long-horizon autonomous coding and engineering tasks. The model, available with a 1-million-token context window, achieved higher scores than OpenAI's GPT-5.5 on multiple industry-standard coding benchmarks, including SWE-bench Pro and FrontierSWE. GLM-5.2 is released under an unrestricted MIT open-source license, allowing enterprises to download, customize, and run it locally, offering a cost-effective alternative to proprietary models. Its API pricing is also significantly lower than some Western rivals.

VentureBeat
Apple May Transition macOS Naming to Version Numbers
Technology
2 minutes ago

Apple May Transition macOS Naming to Version Numbers

Apple appears to be considering a shift in how it names its macOS software platform. Unlike other Apple software that typically uses version numbers, macOS has historically featured unique brand names, such as 'macOS Golden Gate'. However, recent indications suggest the company may be moving towards a numbered versioning system for its operating system.

9to5Mac
Apple Supplier Tata Cleared by Indian Regulator on Pollution Concerns
Technology
2 minutes ago

Apple Supplier Tata Cleared by Indian Regulator on Pollution Concerns

Apple supplier Tata has avoided regulatory action at one of its iPhone component plants located in India. An Indian pollution regulator had previously raised concerns regarding potential wastewater contamination at the facility. The regulatory body subsequently dropped its scrutiny after Tata addressed the issues presented by the regulator.

9to5Mac

By the numbers

Fainaron — live counters

Updated every 30 seconds. Automatically — no human edits.

Total Articles

18.6K

Visitors Today

802

This Month

2.4K

Lifetime Visitors

2.4K

Article Views

27.2K

Pageviews Today

5.7K

Pageviews Lifetime

19.9K

Last 30 Days

2.4K

as of 6/16/2026, 10:11:25 PM