Loading article…
Microsoft 365 Copilot faces a critical vulnerability, dubbed SearchLeak, that could expose sensitive data, with over 1,878 reports of Copilot problems, and a
| At a glance | |
|---|---|
| Company | Microsoft |
| Product | Microsoft 365 Copilot |
| Vulnerability | SearchLeak |
| Reports of problems | 1,878 |
The SearchLeak exploit works by crafting a specific Microsoft 365 Copilot Search URL that includes malicious code, which, when clicked, allows the attacker to scan the victim's inbox, grab confidential items, and sneakily embed that data into a hidden image tag [1]. The vulnerability bypasses standard anti-phishing filters because the attack is delivered through a completely legitimate, trusted Microsoft domain link. Microsoft has mitigated the issue directly on its backend after receiving the report from Varonis Threat Labs [1].
Meanwhile, Microsoft has announced the general availability of Copilot Cowork, its AI-powered agentic workspace, which is designed to handle complex and long-running tasks across multiple tools and data sources [3]. The feature, which was previously available through the company's Frontier preview program, is now rolling out worldwide for Microsoft 365 Copilot customers. More than half of the Fortune 500 companies have already used Copilot Cowork during the preview phase [3]. The company has also introduced spending controls, usage limits, and budget management tools to allow administrators to monitor and manage AI-related expenses [5].
| Comparison | Copilot Cowork | Claude Cowork |
|---|---|---|
| Cost per prompt | 30-40% cheaper | - |
| AI models | Anthropic's Opus 4.8 and Sonnet 4.6 | - |
The SearchLeak vulnerability and the recent outage highlight the importance of security and reliability in AI-powered productivity tools. As Microsoft continues to develop and roll out new features, such as Copilot Cowork, the company must ensure that its tools are secure and reliable to maintain user trust. The impact of these issues on Microsoft's competitive position in the market remains to be seen.
Coverage is mostly measured — 149 of 149 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 5 outlets · Jun 18, 2026 · How we report
Researchers showed that malicious instructions can be hidden in a Word document, which Copilot may execute when generating or editing a new document, allowing the instructions to propagate to subsequent files.
Microsoft has implemented several focused mitigations, recommends installing the latest updates, employing multiple security layers, and reviewing AI‑generated content before use.
Microsoft intends to launch a unified Copilot "super app" that combines chat, coding, coworking, and autonomous Autopilot features for both consumer and business markets later in the year.
Microsoft reports approximately 30 million paid Copilot users among its 450 million business seats.
Experts argue that distinguishing instructions from data at the model or platform level is necessary to prevent similar injection attacks, but it requires industry‑wide architectural changes that are not yet in place.