One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation

One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation

•

Episode description

One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation

Two critical vulnerabilities demand immediate attention from UK businesses today. Researchers have disclosed SearchLeak, a prompt injection vulnerability chain in Microsoft 365 Copilot Enterprise that allows attackers to steal data from mailboxes, OneDrive, and SharePoint with a single malicious link. The attack exploits Copilot’s AI assistant functionality to exfiltrate sensitive information without further user interaction. Meanwhile, Cisco Talos reports active exploitation of authentication bypass vulnerabilities in Cisco Catalyst SD-WAN infrastructure by the sophisticated threat actor UAT-8616, who is deploying multiple command-and-control frameworks including Sliver and Godzilla for persistent network access. Most UK SMBs don’t run SD-WAN directly but face indirect exposure through managed service providers. Both threats target infrastructure that organisations trust by default but rarely examine closely. The episode provides specific verification steps for IT providers and MSPs, emphasising the gap between vendor patches and organisational verification as the primary source of security incidents.

Chapters

  • Introduction Mauven opens with an urgent warning about a one-click data theft vulnerability affecting Microsoft 365 Copilot Enterprise users, then previews coverage of active Cisco SD-WAN exploitation.
  • SearchLeak: M365 Copilot as a Data Theft Tool Analysis of the SearchLeak vulnerability chain in Microsoft 365 Copilot Enterprise. The prompt injection attack allows attackers to use specially crafted URLs to instruct Copilot to search and exfiltrate data from mailboxes, OneDrive, and SharePoint. Microsoft has patched the vulnerability, but verification of deployment through MSPs is critical. Recommendations include confirming patch status, reviewing Copilot licence assignments, applying least privilege access controls, and exercising caution with links triggering Copilot interactions.
  • Call to Action Reminder to follow the show and share with colleagues who need daily threat intelligence.
  • Cisco SD-WAN: Active Exploitation by UAT-8616 Cisco Talos reports active exploitation of CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller and Manager. The sophisticated threat actor UAT-8616 is deploying Sliver, Godzilla, AdaptixC2, and Behinder for persistent access to network infrastructure. Most UK SMBs face indirect exposure through managed service providers running this infrastructure. Actions include immediate patching for direct users, verification calls to MSPs regarding their infrastructure and patching status, contract review for incident disclosure terms, and monitoring for anomalous routing changes.
  • Supply Chain Pressure Continues Brief coverage of Arch Linux locking down AUR signups after malicious commits, and Unit 42 analysis of updated obfuscation techniques in Gremlin Stealer infostealer targeting browser credentials.
  • Closing Mauven emphasises that both threats target infrastructure organisations trust without close examination. Final action items: contact IT providers or MSPs to verify M365 patch status and Cisco SD-WAN infrastructure security posture.

Links

No chapters are available for this episode.