
Varonis discovered a three-stage vulnerability chain named SearchLeak that exploits Microsoft 365 Copilot Enterprise Search to exfiltrate emails, 2FA codes, and business documents. The attack uses Parameter-to-Prompt Injection, HTML injection, and CSP bypass via Bing SSRF to access indexed content including SharePoint and OneDrive files. Microsoft's safety guardrails fail when all three stages are combined.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
FBI warns of Kali365 phishing service targeting Microsoft 365