'SearchLeak' POC widens M365 Copilot prompt-injection attack surface

Security researchers disclosed 'SearchLeak,' a proof-of-concept against Microsoft 365 Copilot Enterprise that demonstrates parameter-to-prompt (P2P) injection — where attacker-controlled data flows into search parameters and ultimately into the model's prompt. The finding, covered by CSO Online, reframes everyday AI-enhanced search as a meaningfully larger attack surface than many enterprises assume.
The mechanism matters: as Copilot integrates more deeply with enterprise data and search, the boundary between trusted instructions and untrusted content blurs. P2P injection exploits that blur, potentially coercing Copilot into actions or disclosures the user never intended. Researchers framed it not as a single bug but as a class of risk that grows with every new data connector and search capability.
This lands amid a broader week of AI-security stories — AWS launched its Continuum vulnerability platform and DeepMind published its 'insider threat' agent-defense plan — underscoring that agent and assistant security is now a front-line enterprise concern. For Microsoft, which has aggressively shipped Copilot across Office and just made Copilot Cowork GA, the disclosure is a reminder that the assistant's reach is also its liability. Enterprises should watch for Microsoft's mitigations and treat agent-accessible data sources as part of their threat model.