Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
2026-06-16T02:51:44Z•a98b8f55f2d00787cc281675d7d62371759c1212654774883ecd57a0d0f84cdd
agentic-ai-wormsai-enabled-attackscheck-pointcisacve-2025-8088data-exfiltrationemail-spoofingexchangegithub-compromiseivantimiasmanation-state-espionageoraclepatchingphishingpoC-releaseprompt-injectionransomwareshinyhunterssupply-chain-attackwindows-defenderwinrarzero-day
What happened
A cluster of high-impact incidents and trends from mid-June 2026: a patched three-stage Copilot "SearchLeak" prompt-injection that enabled 1-click data theft; Google disrupted a China-linked espionage campaign that stole RedCAP credentials and exfiltrated research data; ShinyHunters are exploiting an Oracle ERP zero-day against U.S. higher-education institutions; multiple critical zero-days saw active exploitation (Ivanti Sentry exploited within 24 hours of disclosure; an actively-exploited Check Point VPN zero-day); a WinRAR vulnerability (CVE-2025-8088) is being weaponized in campaigns vs. U
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- a98b8f55f2d00787cc281675d7d62371759c1212654774883ecd57a0d0f84cdd
- Enrichment time
- 2026-06-16T02:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.