arstechnica.com 6/16/2026, 11:27:45 AM · external

Microsoft patches critical Copilot AI flaw that leaked 2FA codes

Microsoft patches critical Copilot AI flaw that leaked 2FA codes
CyberSIXT Evidence Panel
Primary Source varonis.com

MICROSOFT recently patched a critical vulnerability in its M365 Copilot AI platform, which allowed hackers to extract two-factor authentication (2FA) codes and other sensitive data from user emails. Researchers from Varonis demonstrated a proof-of-concept exploit called 'SearchLeak' that circumvented existing guardrails by utilizing a Parameter-to-Prompt Injection technique through specially crafted URLs.

This method enabled attackers to access sensitive information from emails and other organizational data simply by having the victim click a link. Despite Microsoft's fix for the vulnerability, the inherent challenges of safeguarding AI systems against such exploits remain, leaving the potential for further attacks as attackers adapt to new defenses.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline