• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Microsoft Patches Copilot Flaw That Let Attackers Steal MFA Codes With One Click

  • SOFX Staff Writer
  • June 17, 2026
(Credit: Primakov / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

Microsoft patched a critical vulnerability in Microsoft 365 (M365) Copilot Enterprise on June 4 that let an attacker steal multi-factor authentication (MFA) codes, emails, calendar data, and organizational files with a single click on a legitimate Microsoft URL.

Varonis Threat Labs researcher Dolev Taler, credited in Microsoft’s CVE-2026-42824 advisory, named the chain SearchLeak. It links a Parameter-to-Prompt (P2P) injection with an HTML rendering race condition and a Content Security Policy (CSP) bypass via Bing server-side request forgery (SSRF).

A crafted URL plants instructions inside the Copilot Enterprise Search query parameter. Copilot reads them as commands, searches the target’s mailbox or files, and embeds the results in an image tag.

“To exfiltrate the data, an attacker crafts a URL that tells Copilot to search the user’s emails, extract the title, and embed it in an image URL,” Taler wrote.

Copilot’s sanitizer wraps output in code blocks after generation ends, but browsers render the incoming stream live. The injected image tag fires before the sanitizer runs, and the chain routes the request through Bing’s CSP-allowlisted “Search by Image” endpoint with stolen data encoded in the path.

MFA codes and password-reset links carry the highest exposure, with account takeover possible before they expire. The attack inherits the victim’s Microsoft Graph permissions, reaching SharePoint documents, OneDrive files, and calendar data across the organization.

Microsoft’s own Common Vulnerability Scoring System (CVSS) 3.1 submission scored CVE-2026-42824 at 6.5, below the 7.5 the National Vulnerability Database (NVD) assigned and below the critical rating Microsoft applied internally. Tenant administrators had no patch to apply. Microsoft resolved the flaw on its backend.

SearchLeak is the third consecutive one-click Copilot exfiltration chain from Varonis, following Reprompt against Copilot Personal in January 2026 and Aim Security’s zero-click EchoLeak in 2025. Each broke through a higher-tier deployment. Varonis confirmed no in-the-wild exploitation.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Ukraine’s AI-Powered ‘Terminator’ Drones Made First Killings Without Human Control

Ukraine’s AI-Powered ‘Terminator’ Drones Made First Killings Without Human Control

by SOFX Staff Writer
June 15, 2026
2

Fully autonomous drones operating without human oversight killed Russian soldiers during a battlefield test in Ukraine about two years ago,...

U.S., Iran Sign 14-Point Deal to End War and Reopen Strait of Hormuz

U.S., Iran Sign 14-Point Deal to End War and Reopen Strait of Hormuz

by SOFX Staff Writer
June 18, 2026
1

The United States and Iran have signed a 14-point memorandum of understanding aimed at ending months of conflict, reopening the...

FBI Foils Drone-and-Sniper Plot on White House UFC Event

FBI Foils Drone-and-Sniper Plot on White House UFC Event

by SOFX Staff Writer
June 17, 2026
5

The FBI has arrested five people in connection with an alleged plot to attack President Donald Trump’s UFC Freedom 250...

Ukraine Wants Foreigners in Half Its Infantry, and Private Firms Will Deliver Them

Ukraine Wants Foreigners in Half Its Infantry, and Private Firms Will Deliver Them

by SOFX Staff Writer
June 12, 2026
2

Ukraine will let private companies recruit, screen, and deliver foreign fighters to its army, and it wants those foreigners to...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Putin Critic Shot Dead in Poland as Belarusians Detained Near Consulate

Putin Critic Shot Dead in Poland as Belarusians Detained Near Consulate

UK Locks In GCAP Contract After Defence Secretary Resignation Forced Starmer’s Hand

UK Locks In GCAP Contract After Defence Secretary Resignation Forced Starmer's Hand

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz