Live Feeds
● TRACKER Updated 49d ago · 34 sources tracked

New attack turned Microsoft 365 Copilot into 1-click data theft tool

Attackers are using ConsentFix and ClickFix methods to steal Microsoft 365 tokens. These tactics use fake prompts and OAuth flows to bypass MFA. The hijacking process takes seconds.

🎙️

Listen to Live Briefing

Real-time synthesized voice briefing · Live Feeds Desk

⏱ ~1 min
Speed:
RSS Source map (34)
Key Developments & Real-Time Context
Text size:
  • ConsentFix and ClickFix attacks use fake prompts and OAuth flows to steal Microsoft 365 tokens.
  • These MFA bypass tactics can hijack accounts in seconds.
  • Microsoft fixed a bug that caused Copilot buttons to disappear for Windows users with Basic licenses in Classic Outlook.
🛡️ Source Corroboration: 34 independent reporting domains (100% confidence) ⏱ Read time: ~1 min

What changed

New reports identify ConsentFix and ClickFix as specific methods for rapid account hijacking.

Live updates

  1. New ConsentFix and ClickFix Attacks Hijack Microsoft 365 Accounts

    Attackers are using ConsentFix and ClickFix methods to steal Microsoft 365 tokens. These tactics use fake prompts and OAuth flows to bypass MFA. The hijacking process takes seconds.

    What's confirmed:

    • ConsentFix and ClickFix attacks use fake prompts and OAuth flows to steal Microsoft 365 tokens.
    • These MFA bypass tactics can hijack accounts in seconds.
    • Microsoft fixed a bug that caused Copilot buttons to disappear for Windows users with Basic licenses in Classic Outlook.
    Sources used for this update (2)
    1. Microsoft fixes bug that removed Copilot buttons in Outlook
    2. ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
    confidence 100%
  2. Microsoft Patches Multiple Critical Copilot Data Theft Vulnerabilities

    Microsoft addressed two critical flaws in 365 Copilot that allowed data exfiltration. One vulnerability enabled the theft of MFA codes via one-click command injection. Another zero-click flaw allowed attackers to steal files and chat logs using hidden prompts in emails.

    What's confirmed:

    • CVE-2025-32711, known as EchoLeak or Copilot SearchLeak, is a zero-click indirect prompt injection vulnerability.
    • EchoLeak affects Copilot integrations in Teams, Outlook, PowerPoint, Excel, and Word.
    • CVE-2026-42824 allowed attackers to steal MFA codes using one-click command injection.
    • Microsoft issued a server-side patch for EchoLeak in June 2025.
    • The EchoLeak exploit bypasses the Cross-Prompt Injection Attempt classifier and Content Security Policy.

    Still unconfirmed:

    • The government issued a warning regarding the Microsoft 365 Copilot security flaw.
    Sources used for this update (5)
    1. EchoLeak exposes data via Microsoft 365 Copilot
    2. Microsoft Issues Critical Patch for Copilot Vulnerability Enabling One ...
    3. Microsoft 365 Copilot Security Flaw Can Put Your Confidential Data At ...
    4. SearchLeak: Why Do Legacy Web Vulnerabilities Persist in AI Agents?
    5. Securing Entreprise AI Agents: How Copilot Studio Agents Work
    confidence 90%
  3. Varonis Discloses CVE-2026-42824 SearchLeak Vulnerability in M365 Copilot

    A critical-severity attack chain allows external actors to steal enterprise data from Microsoft 365 Copilot tenants via a single click. The exploit can exfiltrate company files, emails, and authentication codes. Microsoft has addressed the flaw.

    What's confirmed:

    • Varonis Threat Labs disclosed CVE-2026-42824 on June 15, 2026.
    • The SearchLeak exploit enables an external attacker to exfiltrate sensitive enterprise data from a Microsoft 365 Copilot tenant with a single click.
    • The attack can steal company files, emails, and authentication codes.
    Sources used for this update (2)
    1. SearchLeak: One-Click Data Exfiltration via M365 Copilot
    2. Microsoft Copilot One-Click Flaw Could Expose Data
    confidence 100%
  4. Microsoft Patches SearchLeak Data Theft Vulnerability in M365 Copilot

    Microsoft has fixed a critical vulnerability known as SearchLeak in M365 Copilot Enterprise. The flaw allowed attackers to steal files and 2FA codes using a single click via crafted URLs. This attack utilized parameter-to-prompt injections to compromise the target ecosystem.

    What's confirmed:

    • Microsoft patched the SearchLeak vulnerability identified as CVE-2026-42824.
    • The vulnerability allowed for data theft via a crafted URL.
    • The attack used parameter-to-prompt injections.

    Still unconfirmed:

    • The flaw allowed attackers to steal 2FA codes and files with a single click.
    Sources used for this update (3)
    1. M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
    2. SearchLeak Vulnerability Hits Microsoft 365 Copilot Users
    3. Critical Microsoft Copilot Flaw Allowed File Hijacking
    confidence 90%
  5. Varonis Threat Labs Discloses SearchLeak Vulnerability in Microsoft 365 Copilot

    Varonis Threat Labs identified a vulnerability chain called SearchLeak that converts Microsoft 365 Copilot Enterprise Search into a data theft tool. The attack uses a P2P injection to trick the AI into providing malicious links. This allows attackers to steal data from a target's Microsoft ecosystem.

    What's confirmed:

    • Varonis Threat Labs disclosed the SearchLeak vulnerability chain on June 15, 2026.
    • The flaw turns Microsoft 365 Copilot Enterprise Search into a one-click data theft tool.
    • The attack bypasses Copilot safety controls to steal user data and evade detection.

    Still unconfirmed:

    • The vulnerability chain involves two old-fashioned injections and request forgeries triggered by a P2P injection.
    Sources used for this update (3)
    1. SearchLeak: The One-Click M365 Copilot Bug That Drained Mailboxes ...
    2. Reprompt: The Single-Click Microsoft Copilot Attack that Silently ...
    3. “SearchLeak” Copilot Vulnerability Chain Turns the AI Assistant Into a Data Theft Partner
    confidence 100%
  6. Microsoft 365 Copilot flaw still enables 1-click data theft despite patch

    A critical vulnerability in Microsoft 365 Copilot Enterprise, called SearchLeak, allows attackers to steal emails, MFA codes, and documents via a single click on a legitimate Microsoft link. The flaw was patched in June but remains actively exploitable. Researchers confirm proof-of-concept attacks work without user interaction, using authentic Microsoft URLs to bypass security. Microsoft rates the flaw as critical, though industry experts question broader LLM security approaches.

    What's confirmed:

    • A critical vulnerability in Microsoft 365 Copilot Enterprise, dubbed SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data including emails, passwords, calendar events, and SharePoint documents through a malicious URL.
    • The flaw was addressed in a June patch but remains actively exploitable.
    • Attackers can bypass security with a single click on a legitimate Microsoft link.
    • The exploit chains three bugs into a single attack for data theft.
    • Proof-of-concept attacks work without requiring user interaction.
    • Microsoft rates the flaw as critical.

    Still unconfirmed:

    • Industry experts question broader LLM security approaches, though specifics remain unclear.
    Sources used for this update (2)
    1. Microsoft 365 Copilot can be turned into a one-click data theft tool ...
    2. Microsoft: New attack turned Microsoft 365 Copilot into 1-click data ...
    confidence 93%
  7. Microsoft 365 Copilot flaw still exploited for silent data theft via one click

    A critical vulnerability in Microsoft 365 Copilot Enterprise, called SearchLeak, allows attackers to steal emails, MFA codes, and documents with a single click on a legitimate Microsoft link. The flaw was patched in June but remains actively exploitable. Researchers confirm proof-of-concept attacks work without user interaction, using authentic Microsoft URLs to bypass security. Microsoft rates the flaw as critical, though industry experts question broader LLM security approaches.

    What's confirmed:

    • A single click on a trusted Microsoft domain link can silently steal sensitive corporate data, including emails, MFA codes, calendar details, and confidential files, with no user interaction beyond the click.
    • The vulnerability, named SearchLeak, was patched in June but remains exploitable in active environments.
    • Attackers chain an AI prompt-injection bug with two classic web flaws to turn Copilot Enterprise Search into a silent data-theft tool.
    • Microsoft rates the flaw as critical, though severity assessments vary among researchers.

    Still unconfirmed:

    • The industry's approach to LLM security is fundamentally flawed due to repeated vulnerabilities like SearchLeak.
    Sources used for this update (3)
    1. Critical Microsoft 365 Copilot Flaw Enables One-Click Data Theft
    2. Microsoft 365 Copilot Flaw Let One Click Exfiltrate Emails, MFA Codes ...
    3. Critical Copilot vulnerability allowed hackers to seal 2FA code from users
    confidence 92%
  8. Microsoft 365 Copilot flaw still enables 1-click data theft despite patch

    A critical vulnerability in Microsoft 365 Copilot Enterprise, called SearchLeak, allows attackers to steal emails, documents, and meeting details with a single click on a trusted Microsoft domain link. The flaw remains exploitable despite a June patch, while a separate phishing kit targets Microsoft 365 tokens. Researchers confirm proof-of-concept attacks work without user interaction, exploiting authentic Microsoft URLs to bypass security controls. Microsoft rates the flaw as critical, though severity assessments vary.

    What's confirmed:

    • A vulnerability chain called SearchLeak allows attackers to exfiltrate sensitive Microsoft 365 Copilot Enterprise data through a single click on a legitimate Microsoft domain link.
    • The attack bypasses traditional security controls because it uses authentic Microsoft.com URLs, making it harder for anti-phishing tools to detect.
    • Researchers have confirmed proof-of-concept attacks exploiting SearchLeak work without requiring user interaction beyond clicking a malicious link.
    • Microsoft has rated the SearchLeak flaw as critical, though severity scores from other assessments vary.

    Still unconfirmed:

    • No confirmed link exists between the SearchLeak vulnerability and the Kali365 phishing kit, though both highlight ongoing risks in Microsoft 365 environments.
    Sources used for this update (2)
    1. Microsoft 365 Copilot Vulnerability Exposes Sensitive Data Through One ...
    2. One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal ...
    confidence 95%
  9. Microsoft Copilot flaw turned into 1-click data theft tool despite patch

    A patched flaw in Microsoft 365 Copilot Enterprise, called SearchLeak, allows attackers to steal emails, documents, and meeting details with a single click on a trusted Microsoft domain link. Exploitation persists despite a June patch, while a separate phishing kit targets Microsoft 365 tokens. Microsoft calls the flaw critical, but CVSS scores vary. No confirmed link exists between SearchLeak and the Kali365 phishing kit, though both highlight ongoing risks. Researchers confirm proof-of-concept attacks worked without user interaction.

    What's confirmed:

    • A single click on a legitimate Microsoft domain link could exfiltrate emails, calendar details, and indexed files from Microsoft 365 Copilot Enterprise Search without user prompts or additional interaction.
    • The vulnerability chain, named SearchLeak, bypassed traditional anti-phishing and URL filtering tools due to the use of a real microsoft.com domain.
    • Microsoft assigned CVE-2026-42824 to the flaw and marked it as critical, though CVSS scores conflict—6.5 from Microsoft and 7.5 from the National Vulnerability Database.
    • The flaw was mitigated on Microsoft’s backend in early June, meaning customers require no additional action, though researchers demonstrated a proof-of-concept attack.
    • Data exfiltration via SearchLeak worked even after users closed chat windows, indicating persistent access.
    • A separate single-click attack targeting Microsoft Copilot Personal allowed silent exfiltration of sensitive user data via phishing links, now patched.
    • No confirmed evidence links SearchLeak to the Kali365 phishing kit, which maintains access after multi-factor authentication resets.

    Still unconfirmed:

    • Active exploitation of the SearchLeak flaw persists despite the patch, though this has not been independently verified beyond researcher observations.
    • The Kali365 phishing kit may be leveraging similar techniques to SearchLeak, but no direct connection has been confirmed.
    Sources used for this update (4)
    1. A single click mounted a covert, multistage attack against Copilot
    2. New attack turned Microsoft 365 Copilot into 1-click data theft tool
    3. One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal ...
    4. New One-Click Microsoft Copilot Vulnerability Grants Attackers ...
    confidence 92%
  10. Microsoft 365 Copilot flaw SearchLeak still exploited via 1-click theft attack

    A critical vulnerability chain in Microsoft 365 Copilot Enterprise, called SearchLeak, allows attackers to steal emails, documents, and meeting details with a single click. Microsoft patched the flaw in early June, but new evidence suggests active exploitation persists. Separately, a phishing kit called Kali365 targets Microsoft 365 tokens, maintaining access even after multi-factor authentication resets. No confirmed evidence links SearchLeak to Kali365, but both highlight ongoing risks in Microsoft’s security posture.

    What's confirmed:

    • A vulnerability chain named SearchLeak in Microsoft 365 Copilot Enterprise lets attackers steal sensitive data—including emails, documents, and meeting details—with a single malicious link.
    • The flaw combines three separate vulnerabilities to bypass standard security protections, including those for multi-factor authentication and user permissions.
    • Microsoft applied a server-side patch for SearchLeak in early June, but no user action was required to mitigate the risk.
    • Varonis researchers disclosed the SearchLeak chain, detailing how attackers could craft links to trigger data exfiltration without triggering alerts.
    • A phishing kit called Kali365 targets Microsoft 365 users by stealing authentication tokens and maintaining access even after password or MFA resets.
    • Kali365 operates through Tencent Cloud and is designed to evade detection by persisting beyond standard credential revocation methods.

    Still unconfirmed:

    • Attackers are actively exploiting the SearchLeak vulnerability chain in the wild, though no confirmed cases of exploitation have been publicly reported.
    • The Kali365 phishing kit may be linked to the same threat actors behind SearchLeak, though no direct evidence connects the two campaigns.
    Sources used for this update (3)
    1. New attack turned Microsoft 365 Copilot into 1-click data theft tool
    2. CVE-2026-42824: M365 Copilot SearchLeak Enables 1-Click Email Theft
    3. Inside Kali365, a Device Code Phishing Ecosystem | Huntress
    confidence 95%
  11. Microsoft 365 Copilot patched after one-click data theft flaw

    Microsoft fixed a critical flaw in Copilot Enterprise Search called SearchLeak that allowed attackers to steal emails, MFA codes, files, and meeting details with a single click. The attack chained three vulnerabilities and bypassed standard protections. No evidence of active exploitation has been reported. Microsoft applied a server-side patch in early June without requiring user action.

    What's confirmed:

    • Microsoft patched a critical vulnerability chain in Microsoft 365 Copilot Enterprise Search, named SearchLeak (CVE-2026-42824), which allowed attackers to exfiltrate sensitive data—including emails, MFA codes, OneDrive/SharePoint files, and calendar events—with a single click.
    • The attack relied on three flaws: a parameter-to-prompt injection via the URL 'q' parameter, an HTML rendering race condition, and a Bing server-side request forgery (SSRF) that bypassed Content Security Policy protections.
    • The exploit used a legitimate microsoft.com domain, making it difficult for standard URL filtering and anti-phishing tools to detect.
    • Microsoft applied a server-side fix at the beginning of June 2026, requiring no action from customers.
    • Varonis disclosed a proof-of-concept but reported no observed in-the-wild exploitation of the flaw.
    • The vulnerability affected Microsoft 365 Copilot Enterprise Search specifically, not the broader Copilot platform.

    Still unconfirmed:

    • A separate CoPhish attack using Microsoft Copilot agents to steal OAuth tokens has been reported, but details remain unverified.
    Sources used for this update (12)
    1. New attack turned Microsoft 365 Copilot into 1-click data theft tool
    2. One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
    3. Microsoft Patches Critical SearchLeak Flaw in 365 Copilot
    4. SearchLeak: How We Turned M365 Copilot Into a One-Click Data ... - Varonis
    5. Researchers Reveal One-Click Microsoft 365 Copilot Data-Exfiltration ...
    6. SearchLeak M365 Copilot & Cisco SD-WAN Threat Analysis | SBCSG | The ...
    7. CoPhish Exploit via Microsoft Copilot: OAuth Token Theft Exposes ...
    8. Microsoft Security Blog
    9. DLP for Microsoft 365 Copilot and Copilot Chat | Microsoft Learn
    10. A single click on a Microsoft link could have drained your inbox. Here’s how SearchLeak worked.
    11. Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal ...
    12. How a simple link allowed hackers to bypass Copilot's security ... - ZDNET
    confidence 95%
📊

Community Sentiment: How do you assess this situation?

Voice your perspective · Real-time aggregated sentiment from the Live Feeds community