Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)

Vulnerability
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed files after clicking a trusted microsoft.com link. The chain used the `q` parameter, an HTML rendering race, and Bing's Search by Image as an exfiltration proxy. Microsoft assigned CVE-2026-42824 and said it mitigated the flaw on its backend, while Varonis Threat Labs reported a proof-of-concept rather than observed exploitation.

Related Happenings

KongTuke Microsoft Teams initial access campaign

Campaign
H score42 First: 14.05.2026 15:12 Last: 14.05.2026 15:12 Sources 1

About this happening: The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...

Microsoft Windows 365 Office installation disruption

Service Disruption
H score0 First: 13.05.2026 14:53 Last: 13.05.2026 14:53 Sources 1

About this happening: The Windows 365 service update has introduced a configuration change that is blocking Office downloads and installs for some customers, disrupting access on cloud PCs....

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Storm-1175 high-velocity exploit campaign

Campaign
H score59 First: 06.04.2026 19:56 Last: 06.04.2026 19:56 Sources 1

About this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...

Storm-2561 SEO-poisoning VPN credential-theft campaign

Campaign
H score37 First: 13.03.2026 15:38 Last: 13.03.2026 15:38 Sources 1

About this happening: The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...

Timeline

  1. 15.06.2026 16:00 3 articles · 1mo ago

    SearchLeak chains Copilot Enterprise flaws to steal mailbox and SharePoint data

    Initial Disclosure

    Varonis describes SearchLeak, a three-stage attack chain in Microsoft 365 Copilot Enterprise that combines parameter-to-prompt injection, an HTML rendering race condition, and a Bing SSRF/CSP bypass to exfiltrate mailbox, OneDrive, or SharePoint data through a specially crafted URL. Microsoft assigned CVE-2026-42824 a critical rating and has already fixed it, with no user action required to mitigate the threat.

    Show sources