Back to IntelRead Original Source
Intel Node
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
lowadvisory2026-06-15T15:09:05+00:00source excerpt
tradecraftidentityemail
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak.