๐ Business & Startups๐ Global
Microsoft Copilot Can Be Tricked Into Searching Your Inbox โ And Leaking What It Finds
VentureBeatยทSunday, 21 June 2026

Security firm Varonis disclosed a vulnerability called SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot Enterprise Search. A victim clicks a crafted Microsoft URL, Copilot searches their mailbox, and the results can be exfiltrated to an attacker. Separately, LiteLLM, a widely used AI tool, was found to hand out admin-level API keys improperly.
Why It Matters
If your workplace uses Microsoft 365 Copilot or any AI tools built on LiteLLM, your emails and API credentials could be at risk right now.
๐ Potential Impact + source link
Subscribe to unlock the impact analysis and original source for every story.
