Breach404
Back to Insights
AI Security2 min readJune 15, 2026

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

Microsoft's Copilot had a critical vulnerability that allowed attackers to steal sensitive data through a single malicious link, exploiting how the AI system processes hidden URLs and variables in prompts. Although Microsoft has patched this specific flaw

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free