One Click. M365 Copilot Handed Over Everything.
TL;DR
- CVE-2026-42824, called SearchLeak, made Microsoft 365 Copilot Enterprise Search into a single-click siphon for MFA codes, inbox contents, meeting details, and private SharePoint and OneDrive files. - Microsoft pushed a server-side patch and slapped their highest "critical" label on it. Except their CVSS score doesn&