New attack turned Microsoft 365 Copilot into 1-click data theft tool
…With Microsoft having fixed CVE-2026-42824, there’s no user action required to mitigate this threat. Varonis underscores that familiar, easily contained bugs like SSRF and HTML injection race conditions can…