The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint…

Microsoft fixed a critical Copilot Enterprise Search flaw that could expose emails, calendars, and indexed files through one trusted link.

Varonis chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click data theft path that bypassed phishing filters and CSP protections.

The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.

SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

SearchLeak exploit shows why the industry's approach to LLM security fails over and over.

Microsoft fixed CVE-2025-32711, a critical zero-click vulnerability in M365 Copilot that allowed silent exfiltration of emails, 2FA codes, and documents via

This sneaky attack tricks Microsoft's AI assistant to hand over your data.