A single click on a trusted Microsoft link could have let an
attacker pull emails, calendar details, and indexed files out of
Microsoft 365 Copilot Enterprise Search. Researchers at Varonis
Threat Labs chained three bugs into a one-click exfiltration path
they call SearchLeak. Because the link pointed to a real
microsoft.com domain, traditional anti-phishing and URL filtering
tools were
Read more https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html

