Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

2026-06-16T02:51:44Za98b8f55f2d00787cc281675d7d62371759c1212654774883ecd57a0d0f84cdd
agentic-ai-wormsai-enabled-attackscheck-pointcisacve-2025-8088data-exfiltrationemail-spoofingexchangegithub-compromiseivantimiasmanation-state-espionageoraclepatchingphishingpoC-releaseprompt-injectionransomwareshinyhunterssupply-chain-attackwindows-defenderwinrarzero-day

What happened

A cluster of high-impact incidents and trends from mid-June 2026: a patched three-stage Copilot "SearchLeak" prompt-injection that enabled 1-click data theft; Google disrupted a China-linked espionage campaign that stole RedCAP credentials and exfiltrated research data; ShinyHunters are exploiting an Oracle ERP zero-day against U.S. higher-education institutions; multiple critical zero-days saw active exploitation (Ivanti Sentry exploited within 24 hours of disclosure; an actively-exploited Check Point VPN zero-day); a WinRAR vulnerability (CVE-2025-8088) is being weaponized in campaigns vs. U

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
a98b8f55f2d00787cc281675d7d62371759c1212654774883ecd57a0d0f84cdd
Enrichment time
2026-06-16T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.