Daily brief at 7am Melbourne. Unsubscribe any time.

Wednesday 17 June 2026

The SearchLeak Flaw: How a Critical Microsoft Copilot Bug Turned 2FA Into a Liability

A critical flaw in Microsoft Copilot let attackers silently steal users' 2FA codes — and it's the latest proof that LLM security is still being bolted on as an afterthought.

Lead story

The SearchLeak Flaw: How a Critical Microsoft Copilot Bug Turned 2FA Into a Liability

A critical vulnerability in Microsoft Copilot allowed attackers to steal users' two-factor authentication codes — the very tokens that are supposed to be your last line of defence. Researchers dubbed it "SearchLeak," and the exploit worked by manipulating Copilot's web search functionality to exfiltrate sensitive data from a victim's session without any unusual-looking interaction on the user's end.

The mechanics are straightforward in a grim way. Copilot's search integration, when handling certain crafted prompts, could be coaxed into surfacing live authentication codes from a user's email or messaging context and routing them back to an attacker. No elaborate social engineering required — just the right query, and 2FA essentially became a delivery mechanism for the attacker rather than a barrier.

Microsoft has patched the issue, but the researchers' conclusion carries more weight than the fix itself. The industry keeps treating LLM security as a feature to ship later, rather than a first-principles design constraint. Copilot has deep access to emails, calendars, files, and messages — the kinds of integrations that make it genuinely useful. That same depth makes each new prompt-injection or data-exfiltration vector disproportionately dangerous.

This isn't the first time. The pattern is familiar: a new capability ships, researchers probe the edges, a serious exfiltration bug surfaces, a patch follows, and the industry declares it solved until the next integration lands. "SearchLeak shows why the industry's approach to LLM security fails over and over again," is how Ars Technica framed it — and there's not much to argue with there.

For Australian organisations, Copilot for Microsoft 365 is already broadly deployed across enterprise, government, and education. The Australian Signals Directorate's guidance on AI in government explicitly flags data handling and access scope as risk areas — and this vulnerability is precisely the scenario those warnings describe. Any organisation that took an "it's Microsoft, it'll be fine" approach to Copilot's permission boundaries should revisit that assumption now.

What makes this structurally significant is what it reveals about the AI integration model. When an LLM can read your inbox, schedule your meetings, and query your files, the attack surface isn't just the model — it's everything the model can touch. A conventional app vulnerability affects the app. An LLM vulnerability with broad permissions affects the entire data estate the model was trusted with.

The fix here is a combination of tighter output filtering, better prompt-injection defences, and — most importantly — the principle of least privilege applied to AI assistant integrations. Copilot probably doesn't need write access to everything, and it definitely shouldn't be able to surface authentication tokens in a query response.

Watch for: whether Microsoft publishes a detailed post-mortem on the isolation boundary failures here, and whether other AI assistants with similar email/calendar integrations (Google Gemini, Apple Intelligence) receive equivalent scrutiny from researchers off the back of this finding.

Also today

Amex Hit With OAIC Enforcement Order Over Insider Privacy Breaches

Australia's Office of the Australian Information Commissioner has ordered American Express to implement access controls and governance reforms after a series of insider-driven privacy breaches. Amex has six months to comply. The OAIC's action is a pointed reminder that privacy enforcement here isn't just about external hackers — it's equally focused on whether organisations have adequate internal controls to stop employees from misusing customer data. For any financial services firm operating in Australia, this is a live signal that the regulator is watching access management as closely as breach notification.

iTnews

SpaceX Acquires AI Coding Platform Cursor for $60 Billion

Days after its blockbuster IPO sent its valuation past $2.6 trillion, SpaceX has agreed to buy AI coding assistant Cursor in an all-stock deal worth $60 billion. The move is a bet that autonomous software development is the next frontier — and that owning the tooling layer is as strategically important as owning the rocket. SpaceX told IPO investors it sees a $26 trillion addressable market in AI; acquiring Cursor is its first concrete step at turning that slide into a business. Cursor competes directly with GitHub Copilot and tools backed by Anthropic and OpenAI.

TechCrunch

OpenAI's Leaked Financials Show It's Still Burning Billions

Audited financial documents leaked this week show OpenAI's revenues are growing but remain dwarfed by R&D spend and operating costs, leaving the company losing billions annually. The figures are a reality check on an industry narrative that has treated AI monetisation as largely solved. OpenAI is simultaneously the market leader in consumer AI — ChatGPT still commands nearly 50% market share globally — and running a capital structure that depends heavily on continued external funding. For investors assessing the broader AI sector, the docs are a useful counterweight to valuation exuberance.

Ars Technica

ChatGPT's Market Share Drops Below 50% for the First Time

OpenAI's ChatGPT has slipped below 50% market share among AI assistants for the first time, according to new usage data, even as it retains more than 1.1 billion monthly users. Google's Gemini follows at 662 million users and Anthropic's Claude at 245 million. The headline number masks a competitive shift: a year ago, ChatGPT held well above 60% share. The erosion reflects Gemini's deep integration into Android and Google Search, and Claude's growing traction in enterprise and developer use cases — both of which have strong Australian footprints.

TechCrunch

DragonForce Hid Ransomware Traffic Inside Microsoft Teams Relay Infrastructure

The DragonForce ransomware group deployed custom malware called Backdoor.Turn to tunnel command-and-control communications through legitimate Microsoft Teams relay servers. By routing malicious traffic through infrastructure that most enterprise security tools whitelist as routine collaboration activity, the group made its operations effectively invisible to network monitoring. It's a logical escalation of the "live off trusted infrastructure" playbook — and a reminder that Teams, broadly deployed across Australian government and enterprise, is now an active evasion surface, not just a productivity tool.

Bleeping Computer

China-Linked SprySOCKS Backdoor Ported to Windows With Kernel-Level Stealth

ESET researchers have uncovered two previously unknown Windows variants of SprySOCKS — a backdoor previously thought to be Linux-only — attributed to the China-nexus group FishMonger. Dubbed WIN_DRV and WIN_PLUS, both variants use kernel driver abuse to evade detection and support TCP and UDP communications with hardcoded command-and-control servers. The variants have been used against government targets in Honduras, Taiwan, Thailand, and Pakistan. The discovery significantly expands the threat actor's operational reach and suggests a deliberate cross-platform development effort.

The Hacker News

FIFA World Cup Bug Would Have Let Anyone Hijack the TV Broadcast

A security researcher discovered a vulnerability in FIFA's online management systems that would have given any unauthenticated user the ability to modify the live TV stream for every World Cup match. The flaw involved access control failures in an internal broadcast management platform, and the researcher was able to navigate several interconnected internal systems before responsibly disclosing it. FIFA has since fixed the issue. Given that the 2026 World Cup is currently underway across the US, Canada, and Mexico, the potential blast radius — billions of simultaneous viewers — makes this one of the more consequential bugs disclosed this year.

TechCrunch

Attackers Are Actively Exploiting Three Critical Fortinet FortiSandbox Flaws

Threat intelligence firm Defused has confirmed active in-the-wild exploitation of three critical vulnerabilities in Fortinet's FortiSandbox, including CVE-2026-39813 (CVSS 9.1), a path traversal flaw in the JRPC API. One of the three CVEs was patched just last week, meaning attackers moved almost immediately after public disclosure. FortiSandbox is widely deployed in enterprise and government environments as a malware analysis platform — an irony not lost on defenders. Fortinet has released patches for all three; if your organisation hasn't applied them, the window for doing so without incident is closing fast.

The Hacker News

Atomic Arch Supply Chain Attack Poisons 1,500 AUR Packages

A supply chain attack against the Arch User Repository (AUR) — the community-maintained software collection for Arch Linux — compromised approximately 1,500 packages by uploading malicious versions. Arch Linux's maintainers suspended new account registrations in response while they worked through remediation. AUR packages are widely used by developers and technically sophisticated users who tend to run Arch on workstations and build servers. The attack is a useful case study in how open, community-driven package ecosystems trade convenience for supply chain auditability — a tension that applies equally to npm, PyPI, and similar repositories used heavily in Australian software development.

SecurityWeek

OpenAI Publishes Deployment Simulation Method to Predict Model Behaviour Before Release

OpenAI has published research on a technique called Deployment Simulation, which uses real conversation data collected after a model ships to build a simulation environment for testing subsequent models before they go live. The aim is to catch safety and behaviour regressions that don't surface in standard benchmarks by grounding evaluation in how actual users interact with the system, not how researchers expect them to. It's a methodological step forward for pre-deployment safety evaluation — and notable timing, given the ongoing policy debate about whether AI labs are self-regulating responsibly.

OpenAI Blog

UK to Require ID or Face Scan for New Social Media Accounts From 2027

The UK government has confirmed that creating a new social media account will require users to verify they are 16 or older via an ID document upload or facial age estimation scan, with the requirement taking effect from spring 2027. Security researchers have raised two immediate concerns: the checks are easy to circumvent with basic social engineering or document fraud, and centralising biometric and identity data at platform level creates a significant new breach risk. Australia's Online Safety Act gives the eSafety Commissioner comparable age-verification powers; this UK rollout will serve as an early stress test of the model before Canberra is forced to make similar calls.

Bleeping Computer

Sources consulted