Microsoft fixed CVE-2025-32711, a critical zero-click vulnerability in M365 Copilot that allowed silent exfiltration of emails, 2FA codes, and documents via

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint…

Microsoft fixed a critical Copilot Enterprise Search flaw that could expose emails, calendars, and indexed files through one trusted link.