The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

First reported 15 Jun 2026 · 11d ago

Coverage timeline

15 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

It demonstrates how prompt injection with hidden URLs can exfiltrate data from AI assistants like Copilot, a direct risk to enterprise users.

A three-stage 'SearchLeak' attack against Copilot enabled 1-click data theft using hidden URLs and other variables, part of a new class of AI prompt-injection issues. The vulnerability has now been patched.

Why it matters

It demonstrates how prompt injection with hidden URLs can exfiltrate data from AI assistants like Copilot, a direct risk to enterprise users.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS