June 20, 2026
- SearchLeak (CVE-2026-42824) chained prompt injection, a race condition, and a CSP bypass in Microsoft 365 Copilot Enterprise Search into a one-click exfiltration of emails, calendar data, indexed files, and even MFA codes — all via a genuine microsoft.com link that defeated URL filtering. Now patched. The Hacker News, SC World
· AI & Model Security
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- Varonis disclosed SearchLeak (CVE-2026-42824), a one-click chain in Microsoft 365 Copilot Enterprise Search combining prompt injection, a race condition and a CSP bypass to exfiltrate emails, files and even MFA codes — using a real
microsoft.com link that defeats URL filtering. Now patched (The Hacker News, Dark Reading).
· AI & Model Security
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- Microsoft 365 Copilot "SearchLeak" (CVE-2026-42824) chained prompt injection, a race condition, and a CSP bypass into one-click exfil of emails, calendar, indexed files, and MFA codes — all from a legitimate microsoft.com link that defeated URL filtering. Now patched by Varonis disclosure (The Hacker News, Dark Reading).
· AI & Model Security
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
- Microsoft 365 Copilot "SearchLeak" chained prompt injection, a race condition, and a CSP bypass into a one-click data-exfiltration path that could pull emails, calendar data, indexed files, and even MFA codes — all via a link pointing at a legitimate microsoft.com domain, defeating URL filtering. Tracked as CVE-2026-42824 and now patched. Varonis Threat Labs, The Hacker News.
· AI & Model Security
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists