Picture an attacker pulling your CFO’s last quarter of email, the board calendar, and a stack of indexed Word docs out of Microsoft 365 Copilot Enterprise Search. The only thing the victim clicked was a real microsoft.com URL. That’s what Varonis Threat Labs proved this week with SearchLeak, a three-bug chain against Copilot’s Enterprise Search. No malicious domain. No fake login page. No alert from your URL filter. Just trusted infrastructure betraying its users in a way every cybersecurity team should be modeling today.

The same week, a ransomware crew calling itself The Gentlemen shut down Australia’s second-largest sugar producer mid-harvest, and a cyberattack on Russian tech firm Astral knocked out cash registers, document signing, and corporate email for a full week. Different attackers. Different industries. Same lesson: the infrastructure your users trust the most is now the easiest path inside.

Borrowed Trust Did The Work For The Attacker

SearchLeak chained three flaws in Copilot Enterprise Search. The first leaked an internal identifier through a Copilot prompt. The second let researchers craft a search URL on a legitimate microsoft.com host that triggered an arbitrary search query when an authenticated user opened it. The third returned indexed contents (mailbox, OneDrive, SharePoint, indexed PDFs) directly in the response body, where the attacker could harvest them via an out-of-band channel.

The damage profile is the part defenders need to chew on. Anything Copilot had been told to index, the attacker could pull. Emails. Meeting notes. The HR folder. Multi-factor codes pasted into a draft email. Indexed files that nobody remembered were still in scope. One click, no executable, no macro, and the legitimate AI assistant did the exfiltration on behalf of the attacker.

The link pointed to a real microsoft.com domain. Traditional anti-phishing and URL filtering tools had nothing to flag.

Microsoft 365 Copilot SearchLeak vulnerability chain
The SearchLeak chain abused a microsoft.com URL to pull Copilot-indexed mailboxes and files.

Microsoft has patched the chain. The lesson sitting underneath it is bigger than a CVE. AI assistants with broad read scope are now the highest-value target a tenant operates, and the trust users place in a familiar domain is no longer a meaningful safety signal. SearchLeak is the second high-impact one-click Copilot flaw disclosed in the last twelve months. It won’t be the last.

The Same Pattern Just Stopped A Sugar Mill

Mackay Sugar didn’t lose data to an AI plugin. The Gentlemen ransomware crew hit the company’s IT environment, and production at multiple mills halted while the harvest was still rolling in. Australia’s second-largest sugar producer is now running an incident response playbook in the middle of crushing season. Downtime in a mill measures in trucks queued, cane spoiling, and grower contracts at risk.

Astral’s customers in Russia spent a week without functioning cash registers, regulated-goods sales, customer portals, corporate email, or digital-certificate authentication. The vendor was the target. The damage landed on every business that depended on the vendor.

Velvet Ant, the China-linked group documented by Sygnia this week, sat inside an organization’s authentication stack for nearly a decade. They owned PAM. They owned sshd. They owned the path every privileged session had to walk through. Three different stories, one shape: a trusted layer, owned, used to harm the people who built operations on top of it.

The implication for any threat detection program is brutal. The familiar Microsoft URL, the long-trusted authentication daemon, the SaaS vendor your billing department can’t function without; all of them are surfaces an attacker can borrow against your users’ trust. Defense in depth has to assume one of those will turn, and the next layer has to catch it.

Lock Down The AI Surface You Just Bought

If you’ve rolled out Microsoft 365 Copilot, Glean, ChatGPT Enterprise, Google Gemini for Workspace, or anything similar, treat the index as a privileged data store, because that’s what it is. Practical security hardening starts with steps you can take this week:

  • Inventory the index. List every mailbox, drive, SharePoint site, and channel the assistant can read. Anything in scope is exfiltrable through a one-click flaw. Stale data comes out.
  • Apply least privilege to the connector. Restrict the assistant’s read scope to current data. Old project archives, departed-employee mailboxes, and “just in case” folders are pure liability.
  • Lock down outbound from the AI plane. If your assistant can fetch external URLs or render markdown images from arbitrary hosts, that’s the exfil channel. Allowlist destinations.
  • Treat trusted-domain links as untrusted. Phishing-resistant MFA on every authenticated session, short token lifetimes, conditional access tied to device posture. Anchor trust in session state, well above hostname reputation.
  • Run brute-force and anomaly controls on every auth endpoint that touches the AI plane. SaaS integrations, OAuth grants, service principals. Stale ones get rotated or removed.
  • Log every AI tool call. Prompt text, retrieved documents, outbound calls. If you can’t reconstruct what the assistant read for a user yesterday, you can’t run incident response on it.
  • Rehearse the one-click AI compromise. Tabletop the SearchLeak shape with your IR team. Who revokes tokens? Who scopes the blast radius? Who tells the data subjects what was indexed?

None of that requires a new tool. It requires owning the controls on the AI surface the way you already own controls on a domain controller. A serious cyber security program in 2026 budgets time for assistant inventories and AI tool call telemetry the way it budgets for endpoint patching, because the blast radius of a single click against an indexed tenant is now larger than the blast radius of a missed Windows update on a kiosk.

SearchLeak is fixed. The next chain is being written. Build the controls that catch it before the vendor ships the patch.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.