Microsoft’s Copilot Keeps Getting Hacked the Same Way — and Enterprise Defenders Can’t Stop It (opens in new tab)
Varonis researchers turned Microsoft 365 Copilot into a one-click corporate data vacuum for the third time — and enterprise IT teams can do nothing except wait for a backend patch. The SearchLeak exploit, now assigned CVE-2026-42824, shows the same structural weakness that has been exploited twice before is still not fixed at the architectural level.
Read the original article