Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Security researchers at Varonis Threat Labs discovered a critical vulnerability chain called SearchLeak that could allow attackers to exfiltrate sensitive data from Microsoft 365 Copilot Enterprise Search through a single click on a legitimate Microsoft domain link. The attack bypassed traditional security controls because it used authentic microsoft.com URLs, making it difficult for anti-phishing
AIHackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Cybercriminals conducted a sophisticated five-month espionage operation targeting a senior executive at a major global stock exchange, exfiltrating email data through legitimate cloud services like Dropbox and OneDrive to evade detection. The attackers used small, repeated data transfers that mimicked normal cloud traffic patterns, demonstrating advanced tradecraft focused on intelligence gatherin
