<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Phishing-Bypass on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/phishing-bypass/</link><description>Recent content in Phishing-Bypass on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 15 Jun 2025 15:09:05 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/phishing-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft 365 Copilot SearchLeak Flaw: Data Theft Risk</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-365-copilot-searchleak-one-click-data-exfiltration/</link><pubDate>Mon, 15 Jun 2026 15:09:05 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-365-copilot-searchleak-one-click-data-exfiltration/</guid><description>Varonis uncovered a one-click exploit chain in Microsoft 365 Copilot Enterprise Search that could exfiltrate emails, files, and MFA codes via a trusted Mic</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html">The Hacker News</a></p>
<hr>
<p>Researchers at Varonis Threat Labs discovered a chain of three vulnerabilities in Microsoft 365 Copilot Enterprise Search, dubbed &lsquo;SearchLeak&rsquo;, that could be triggered by a single click on a legitimate microsoft.com link. The attack could silently exfiltrate emails, calendar entries, indexed files, and MFA codes without any obvious warning signs. Because the malicious link originated from a trusted Microsoft domain, standard phishing filters and URL-blocking tools would not have flagged it.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Verify that Microsoft&rsquo;s patch for the SearchLeak vulnerability chain has been applied across your Microsoft 365 tenant and review Copilot Enterprise Search permissions to ensure data access is scoped to least-privilege. Additionally, consider whether your existing DLP and CASB controls can detect abnormal Copilot-driven data access patterns, as perimeter URL filtering alone is insufficient against same-domain attack chains.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html">One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes</a></p>
]]></content:encoded></item></channel></rss>