惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
GbyAI
GbyAI
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Know Your Adversary
Know Your Adversary
Project Zero
Project Zero
G
GRAHAM CLULEY
T
Threatpost
T
Threat Research - Cisco Blogs
博客园 - 叶小钗
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
IT之家
IT之家
月光博客
月光博客
C
CXSECURITY Database RSS Feed - CXSecurity.com
W
WeLiveSecurity
阮一峰的网络日志
阮一峰的网络日志
C
Cisco Blogs
S
Schneier on Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Visual Studio Blog
宝玉的分享
宝玉的分享
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Last Week in AI
Last Week in AI
T
Tenable Blog
V
V2EX
I
Intezer
T
Tailwind CSS Blog
博客园_首页
S
Security @ Cisco Blogs
量子位
PCI Perspectives
PCI Perspectives
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
人人都是产品经理
人人都是产品经理
SecWiki News
SecWiki News
小众软件
小众软件
Spread Privacy
Spread Privacy
D
DataBreaches.Net
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
Application and Cybersecurity Blog
Application and Cybersecurity Blog
C
CERT Recently Published Vulnerability Notes

Latest from Windows Central

"An unmatched upgrade opportunity": Intel's new Core Series 3 mobile CPUs target "value buyers"… "There are over 5,700 combinations.": I attended Panasonic's USS Intrepid press conference and saw 10Gbps, Wi‑Fi 7 and on‑device AI in the new Toughbook 56, but should you swap out your Toughbook 55? "We "So Mac folks feel comfortable": Microsoft Microsoft thinks you'll want an Xbox Controller and 1 year of Microsoft 365 and Xbox Game Pass over a MacBook Neo "Microsoft fired the skilled people, leaving flowchart followers": Microsoft's Security Response Center is being blamed for the zero-day BlueHammer exploit leak, but I can't tell who's right "Thank you to every Greymane": Crimson Desert shows no signs of slowing down, topping over 5 million sales… "Another all-round excellent mini PC:" Beelink's discounted desktop is fantastic for intensive work and… Xbox's Starfield gets Nintendo Switch 2 rating days after its PS5 release, keeping hopes for a port of Bethesda's RPG alive — here's what we know "The stuff that we're seeing is really well put together": Xbox game publishing chief says Forza Horizon 6 takes him back to the golden years of racing games Microsoft's Xbox games lead Matt Booty says its studios are in a "culture of cultures" and work together more than you think — Blizzard is even helping with Fable Rumored feature coming to Steam that will help you track prices, and Microsoft should copy it immediately for Xbox and… Xbox and Best Buy want to help you build your first video game in 2026 Microsoft prepares display upgrades and two stage launch for new Surface Pro and Surface Laptop with Intel and… Someone discovered Seagate's Xbox Storage Expansion cards can be used on PC — which has made their value more… ID@Xbox makes a bold claim — “Games launching day one into Game Pass… do very well on other platforms… Before Forza Horizon 6 takes us to Japan, let's remember where the legend began almost 14 years ago "Users can now simply ask what happened": AppControl's optional AI integration gives you in-depth PC diagnostic history in plain English — It works with popular LLMs, but I'll use offline models for added security Our friends at Tom's Guide are upgrading: Here's what it means, and how our sister site's overhaul… "Quantity over quality is not always the answer": WWE 2K26 comes close to being the best in the world, but yearly releases are holding it back I "This is one headset that absolutely will not disappoint anyone": Our favorite Xbox headset raises the bar for sound quality with a price that's lower than I expected "One of the better laptops I’ve encountered and one I’d happily use daily": This high-end ThinkPad is a solid bet for professionals — especially after this generous discount I've finally found a loophole to block a specific type of YouTube ads, and it won’t cost you a dime: Just a… www.windowscentral.com "The Lotus guys probably figured it didn't matter to be wrong": Excel thinks 1900 was a leap year because of a small shortcut taken in the '80s — I'll think of this next time I want to cut corners Starfield's sales on PlayStation 5 make me wonder why Xbox even bothered... was this worth devaluing exclusivity? Overwatch Season 2 is LIVE! Xbox Your Xbox Storage Expansion Cards can have a life after the console if you get a simple adapter for your PC Microsoft is hiking Surface Prices, but one of its best laptops is dodging it with this BIG discount Subnautica 2 publisher changes from Krafton to the game Metro 2039 will be "darker than anything you Surface Hub is dead: Microsoft pulls the plug on its 50-inch and 85-inch collaborative touch displays Microsoft says its MAI-Image-2-Efficient AI model slashes costs by 41% while boosting speed by 22% (and maintaining… Mindwarping Morrowind-like Steam gets an ARM native build for Kingdom Come II, while PC Game Pass players are left waiting Alienware just shook up the budget QD-OLED market with its new AW2726DM — Are the compromises worth the low price? Microsoft's crazy Surface price hikes are pushing me to Apple: I can no longer recommend Surface over a MacBook or… Windows Wrap: Snapdragon X PCs are the latest victims of lazy takes and willfully ignorant tech journalists “I stopped digging through folders”: How OmniSearch changed the way I find files on Windows 11 "The sound quality and comfort are excellent": This PC gaming headset with low latency is great for players who use multiple devices at a budget price "What else were Steam Deck users to do but create their own solutions?": I watched Valve's Linux-first handheld turn into a Windows 11 experiment in its community Is Valve prepping its own AI for Steam? Is Valve prepping its own AI for Steam? “We have discontinued SaRA”: Microsoft replaces its Windows 11 Recovery Assistant — here’s how… "An ode to the Horde:" A ramble on what World of Warcraft's most iconic faction means to me — and a… “Truthfully, I still think Bethesda is just part of something that is not authentic and is not genuine” — Pete Hines reflects on Bethesda after Microsoft’s acquisition “As of January 2026… Drew Murray is now working on the StarCraft shooter” — this report could be the clearest sign yet that the project is moving forward Let's talk about it: Which Xbox console is the best-looking of all time and why is it the Xbox One X? "I didn't know a $50 controller could be this good": this PC gamepad with Hall Effect sticks was already a bargain, but it's now an absolute steal "It still won’t be my dream Surface Pro": The missing piece Microsoft never built vanished — and… Project Helix “Actually lets you test its new features”: Why Microsoft’s Windows 11 Insider overhaul finally feels… Snapdragon X2 laptops need a quick update to stop getting the wrong graphics drivers "The pro-aim function is like cheat mode for shooters": Who needs Xbox's Elite controller when this… "This genuinely puts what Microsoft makes to shame": Someone built the best-looking app for Xbox Cloud Gaming… Microsoft says Windows 11's bugs are all "resolved": At least the ones it knows about — and new… How Red Bull Wololo turned Age of Empires into a headline esports event "Repeated choices to serve their business over their customers": Mozilla accuses Microsoft of using 'dark patterns' to force its Copilot AI on Windows 11 users "I’ve died more times than I can count": This side-scrolling roguelike is an ID@Xbox triumph. Say hi to… The original Xbox was going to be a lot like Project Helix, says ex-Microsoft gaming exec — here's why the first plans for a console-PC hybrid didn't work out "We are rocking on bringing new Xbox console features!": Xbox is soliciting ideas for new features directly.… Former Microsoft Xbox VP says AI is "the big question mark" for the future of gaming — he believes "There won't be a line where it's 'AI' and 'not AI' anymore" Windows and Xbox are now prioritizing user feedback in a huge pivot ... but why now? I can't help but be suspicious… "This is exactly the kind of thing driving me away from Windows": even Edge users don't want this new… Xbox handheld owners finally get the one feature they’ve begged for, and it instantly fixes one of the… "The CRT revival is real": I'm amazed by the community efforts to keep CRT gaming alive — and how OLED could be its renaissance for modern gamers "Gaming just got smoother on Snapdragon": You can finally customize your gaming gear on Windows on Arm Microsoft finally begins removing Copilot from Notepad on Windows 11 — but the AI still persists Fresh Xbox discoveries point to "Duet" codename: A possible companion to "Triton" and more Game Pass… NASA's Artemis II photos will give your Xbox dashboard a serious glow-up, and I didn't even know you could do… "I can't recommend this mouse enough": Logitech's unconventional design will save your wrists and… Microsoft broke Windows 11 search by trying to fix it: Here's what happened "Listening to how we can keep making it better for you": Windows Insider meetups are coming back after years away, connecting Windows 11 users with Microsoft "Reclaiming my screen's real estate": Google Chrome is finally launching vertical browser tabs to catch… Ex-Microsoft gaming VP reveals why Xbox was greenlit despite how “unlikely” it was — “they saw it as a hedge against the threat” of Japan in tech Oop, Xbox's Halo: Campaign Evolved release date may have just leaked thanks to a retailer's mistake — it might have a Deluxe Edition with Early Access, too “Still one of my favorites”: This dependable 2‑in‑1 is discounted again while modern laptops remain… Xbox is finally giving Achievements a huge update with several new features — “We stood up a dedicated team… “Wait, Windows uses less?”: I break down the surprising requirement that flips the Linux vs. Windows script ChatGPT’s refusal to admit mistakes is getting out of hand, and this exchange proves it If you bought an Xbox controller recently: Read this — Microsoft says you might be eligible for free batteries. Dell is scrubbing its failed Premium brand from existence, but who cares when you can save almost $900 on an XPS 14? "Raptor Lake will continue to be abundantly available": Intel exec makes a case for its older chips as RAM prices soar, but are they actually worth buying in 2026? Here's a closer look at the gigantic Forza Horizon 6 Japan map, easily the greatest in the series' history "I hope NVIDIA's legal team lets this slide": I dive into OpenNOW, an open-source GeForce Now alternative that's trending in cloud gaming — for good reason "An error was made": We asked ASUS why Zenbook prices are suddenly soaring, and we have bad news Four new features I found in the Forza Horizon 6 preview that will change how you play the game I finally played Forza Horizon 6 and Japan is a spectacle the likes of which we've never seen “I’m already sold”: Xbox’s new Forza Horizon 6 limited‑edition accessories are (almost) here — and they might be even cooler than I expected ASUS’ Zenbook A16 shows why Microsoft must rethink Copilot+ PC branding "I can't stop laughing": I might have a reason to press my Copilot key as this absurd Windows 11 app adds… Microsoft's Azure cloud platform problems stem from AI, according to a former engineer: "Those disruptions… Xbox Game Pass is losing one of its best games at the worst possible time — get it now while it's cheap… “I finally found something that just works”: I explain the open‑source screenshot tool that beat Snipping Tool and ShareX for me — and why it might become your new default Xbox Game Pass' April lineup brings this surging Call of Duty game, and one of last year's biggest additions is coming to more tiers — plus, Hades 2, DayZ, and more "This was not opportunistic. It was precision." — How North Korean hackers used Microsoft Teams and Slack to compromise Windows PCs with an elaborate ploy I compared Lenovo Qira to HP IQ in a battle of on-device AI intelligence — Are these finally the assistants… Is this the perfect Windows app to emulate? Microsoft needs to take notes.
Attackers tricked Copilot into leaking sensitive data through Bing
https://www.windowscentral.com/author/kevin-okemwa · 2026-06-17 · via Latest from Windows Central
The Microsoft 365 Copilot app is displayed on a smartphone
A significant vulnerability has been discovered in Copilot. (Image credit: Getty Images | Thomas Trutschel)

While generative AI has driven remarkable advances in medicine, education, computing, and beyond, it continues to spark serious concerns about security and privacy among users.

Recently, cybersecurity firm Varonis Threat Labs found a way to exploit Microsoft Copilot to steal all sorts of personal and enterprise data, which it dubbed SearchLeak (Ars Technica). As detailed by security sleuth Dolev Taler, SearchLeak is a “three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon.”

Taler noted that the vulnerability clearly illustrates how AI-powered threats are evolving from classic bugs, making them increasingly dangerous. "Together, these vulnerabilities show how AI can create new paths into systems that build on older weaknesses while remaining extremely difficult for security teams to detect," the researcher added.

How does SearchLeak work? It's an AI-specific vulnerability called a parameter-to-prompt injection. In this case, an attacker will send an unsuspecting user a malicious link that contains a “q parameter” intended for natural language search queries.

Perhaps more concerning, the parameter can be embedded into a legitimate URL. As a result, the researcher explained that Copilot’s AI engine interprets the URL not only as a search query but also as executable instructions.

Consequently, if a user clicks the link, it opens Microsoft 365 Copilot Search, which interprets the parameter as instructions to search their email. Copilot then generates an output that embeds sensitive data into an image URL and exfiltrates it via Bing.

The search functionality is exactly what attackers need, because even with limited capabilities, a user with access to critical information is enough. To exfiltrate the data, an attacker crafts a URL that tells Copilot to ‘Search the user’s emails,’ extract the title, and embed it in an image URL.

Varonis Threat Labs

While Microsoft indicated that the vulnerability wasn't exploited and has since been patched, it labelled ot a "critical." This incident opens up a broader discussion about the dangers of AI in enterprise.

“Since SearchLeak targets the Enterprise tier of Microsoft, the blast radius isn’t limited to personal data—it’s able to surface anything the user has access to inside the organization including emails, meeting invites and notes,” Varonis indicated. SharePoint documents, OneDrive files, and other indexed business content. Depending on how M365 is connected to the environment, the blast radius could extend even wider.”

The exploit could give attackers access to sensitive information, including email subject lines and content, MFA/2FA code activations, meeting details, and files indexed by Copilot from unsuspecting users.


Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.


Kevin Okemwa is a seasoned tech journalist based in Nairobi, Kenya with lots of experience covering the latest trends and developments in the industry at Windows Central. With a passion for innovation and a keen eye for detail, he has written for leading publications such as OnMSFT, MakeUseOf, and Windows Report, providing insightful analysis and breaking news on everything revolving around the Microsoft ecosystem. While AFK and not busy following the ever-emerging trends in tech, you can find him exploring the world or listening to music.