INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Copilot SearchLeak Attack Allows 1-Click Data Theft

| 2026-06-15 19:27 CRITICAL HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
The threat of a sophisticated attack is looming, with the latest incident data revealing a novel vulnerability in Microsoft Copilot that could allow attackers to silently exfiltrate user files. This three-stage vulnerability, dubbed parameter-to-prompt Injection (P2P), works as an unknown subset of indirect prompt-injection attacks and needs to be on defender radar screens. The attack can be crafted using the link itself, which opens Microsoft 365 Copilot Search, structured so that whatever prompt is behind the "q" parameter is accepted by the search. This allows attackers to use this link structure as a opening to craft malicious prompts that victims' Enterprise Copilot systems will interpret and respond to. The vulnerability has been patched with a critical score of 6.5 for CVE-2026-42824, but its impact extends beyond just Microsoft Copilot, exposing organizations to unnecessary data exposure and treating AI systems as part of their attack surface rather than trusted abstraction.
Technical Mitigations AI-generated
* Implement Prompt Isolation: Microsoft should implement prompt isolation to prevent indirect prompt-injection attacks like SearchLeak. This can be achieved by using a combination of Content Security Policy (CSP) and input validation mechanisms. * Use Input Validation and Sanitization: Implement robust input validation and sanitization mechanisms in AI-powered enterprise assistants, such as Copilot, to prevent malicious prompts from being executed. This includes validating user input before passing it through the system. * Implement Output Rendering Isolation: Microsoft should implement output rendering isolation to prevent attackers from manipulating the output of search results or other interactive components. This can be achieved by using a combination of CSP and content security policy mechanisms. * Regularly Update and Patch AI-Powered Enterprise Assistants: Regular updates and patches for AI-powered enterprise assistants, such as Copilot, should be implemented to ensure that known vulnerabilities are addressed promptly. Microsoft should also provide clear instructions on how users can update their software to prevent exploitation of these vulnerabilities. * Monitor User Activity and Report Suspicious Behavior: Implement a monitoring system to detect suspicious behavior in user activity, such as search queries or file access patterns. If any unusual activity is detected, the system should report it to Microsoft's security team for further investigation and potential patching.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sn•••••.org
ha•••••.com
at•••••.com
ht•••••.sys
hxxp://••••••••••••••••••••
im•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
PandoraPandoraShai-HuludShai-Hulud CVE-2026-45472CVE-2026-45472 CVE-2026-45481CVE-2026-45481 CVE-2026-42992CVE-2026-42992 CVE-2026-45463CVE-2026-45463 CVE-2026-48579CVE-2026-48579 CVE-2026-44801CVE-2026-44801 CVE-2026-47652CVE-2026-47652 CVE-2026-45586CVE-2026-45586 CVE-2026-45460CVE-2026-45460 CVE-2026-42989CVE-2026-42989 CVE-2026-45658CVE-2026-45658 CVE-2026-44810CVE-2026-44810 CVE-2026-44803CVE-2026-44803 CVE-2026-47655CVE-2026-47655 CVE-2026-41615CVE-2026-41615 CVE-2026-26142CVE-2026-26142 CVE-2026-47289CVE-2026-47289 CVE-2026-45458CVE-2026-45458 CVE-2026-45607CVE-2026-45607 CVE-2026-47291CVE-2026-47291 CVE-2026-45461CVE-2026-45461 CVE-2026-32193CVE-2026-32193 CVE-2026-48574CVE-2026-48574 CVE-2026-42986CVE-2026-42986 CVE-2026-47635CVE-2026-47635 CVE-2026-45497CVE-2026-45497 CVE-2026-49160CVE-2026-49160 CVE-2026-48563CVE-2026-48563 CVE-2026-44799CVE-2026-44799 CVE-2026-44815CVE-2026-44815 CVE-2026-47634CVE-2026-47634 CVE-2026-42985CVE-2026-42985 CVE-2026-45476CVE-2026-45476 CVE-2026-42980CVE-2026-42980 CVE-2026-42987CVE-2026-42987 CVE-2026-41089CVE-2026-41089 CVE-2026-47654CVE-2026-47654 CVE-2026-42905CVE-2026-42905 CVE-2026-44812CVE-2026-44812 CVE-2026-45641CVE-2026-45641 CVE-2026-47644CVE-2026-47644 CVE-2026-33828CVE-2026-33828 CVE-2026-47288CVE-2026-47288 CVE-2026-50507CVE-2026-50507 CVE-2026-45456CVE-2026-45456 CVE-2026-45648CVE-2026-45648 CVE-2026-48567CVE-2026-48567 CVE-2026-42824CVE-2026-42824 CVE-2026-45474CVE-2026-45474 CVE-2026-45657CVE-2026-45657
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthhealth
Incident Timeline
‎October 2003
Threat actors exploited multiple vulnerabilities and zero-day exploits to target Microsoft systems during the June 2026 Patch Tuesday.
‎2026/05/10
Microsoft received heavy blowback on social media after announcing it was considering taking legal action against Nightmare Eclipse, a security researcher who had released an exploit for the Windows BitLocker vulnerability CVE-2026-50507.
industry Media
industry Legal
infrastructure Windows
vulnerability CVE-2026-50507
organisation YellowKey
organisation BitLocker
‎2026/06/02
Shai-Hulud infected Microsoft's public code repositories.
malware Shai-Hulud
general_metric 72 week
‎June 3
Google resolved a whopping 429 vulnerabilities in its latest Chrome browser update on June 3.
general_metric 429 whopping vulnerabilities
‎2026/06/09
One researcher published an exploit for a zero-day bug in Windows Defender after Microsoft released software updates to patch nearly 200 security holes across its Windows operating systems.
organisation Microsoft
infrastructure Windows
general_metric 200 security holes
vulnerability CVE-2026-45586
organisation GreenPlasma
organisation the Windows Collaborative Translation Framework
‎2026/06/10
Threat actors exploited a previously unknown vulnerability in Microsoft's June 2026 Patch Tuesday updates to gain unauthorized access.
‎2026/06/15
Microsoft released patches on June 15, 2026, to fix multiple vulnerabilities including a zero-day flaw.
‎2022/2025
Threat actors exploited a use-after-free condition in the Windows 11 and Server 2022/2025 operating systems to target devices running T1584.004, specifically Windows 11.
infrastructure Windows
tactic T1584.004 - Server
general_metric 11 Windows
‎2012-2025
Threat actors exploited a memory bug in Windows Server 2012-2025 to execute code on affected systems by sending malformed network packets.
infrastructure Windows
tactic T1584.004 - Server
general_metric 10 Windows
‎2026/06/15
Microsoft released June's Patch Tuesday updates, addressing 73 critical vulnerabilities across various software applications and services.
infrastructure Microsoft 365
organisation Microsoft 365 Copilot Search
organisation CVSS
organisation Azure Durable Task SDK
organisation Microsoft Copilot
organisation OneDrive
organisation SharePoint
organisation Slack
organisation Copilot
infrastructure Windows
organisation BitLocker
organisation NTFS
organisation Miasma Supply Chain Worm Burrows Into
organisation Microsoft Repositories
infrastructure 73 Skipping Guardrails Varonis
organisation TITLE
organisation Microsoft
organisation CSP
organisation Content Security
organisation Varonis
organisation SearchLeak
organisation Remote Desktop Client
organisation Microsoft Office
organisation Microsoft Windows
organisation Windows Active Directory
organisation Windows Kerberos Key Distribution Centre
organisation KDC
organisation Windows Graphics
organisation Windows Remote Desktop
organisation Windows Deployment Services
organisation WDS
organisation DHCP Client
organisation Azure Kubernetes Service
organisation AKS
organisation Microsoft Outlook
organisation Microsoft SQL
organisation Elevation of Privilege Vulnerability
organisation DHA
organisation Windows Collaborative Translation Framework
organisation CTFMON
organisation CVE-2026
organisation the Windows Graphics
organisation Integer
organisation Windows Remote Desktop Client
organisation TCP
organisation IP
organisation Windows DHCP Client
organisation Windows Cryptographic Services
organisation Stack
organisation Nightmare
organisation Windows Update
organisation the Windows Collaborative Translation Framework
organisation DoS
infrastructure 9.8
organisation Core Windows Kernel Flaws
organisation HTTP.sys
organisation Identity Control
organisation Identity
infrastructure Android
organisation Windows File Explorer
organisation Android Office
organisation Powerscribe
organisation Heap
organisation Co-Founder of Action1
organisation DHCP
organisation File Explorer and Desktop Preview Flaws
organisation Desktops
infrastructure Ios
organisation Mobile Authentication
organisation Microsoft Azure Network Adapter
infrastructure Linux
organisation Copilot Chat
organisation Microsoft Edge
organisation Microsoft Exchange Online
organisation Microsoft Graph
organisation Network
organisation Cisco Security Firewall
organisation SRU
organisation Snort 3
organisation Patch Tuesday
infrastructure Visual Studio Code
organisation OpenAI’s
organisation the Security Update Guide
organisation Redmond
organisation Microsoft’s Security Update Guide Action1
organisation Storm Center
organisation Restart
organisation BitLocker Device Encryption
infrastructure 4 Download
organisation Remote Work Risks
organisation Hackread.com
organisation Vulnerability Research
‎June 2026
Microsoft released a Patch Tuesday update for June 2026, which fixed 206 security vulnerabilities in various products.
organisation Microsoft
general_metric 206 vulnerabilities
general_metric 32 products
general_metric 3 Snort
organisation Fixes 206 Flaws
‎Tuesday for June 2026
Microsoft released a large number of security patches on June 2026, including fixes for multiple known vulnerabilities and zero-day exploits.
organisation Microsoft Patch
organisation Snort
‎July 14
Nightmare Eclipse is expected to release a batch of zero-day exploits for Windows on July 14.
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
73
Skipping Guardrails Varonis
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
4
Download
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Intelligence Sources