There you have it! Two enterprise AI tools handed attackers the keys in the same two weeks, and m…
June 19, 2026 · 0 likes · 0 comments
AI Cybersecurity
There you have it! Two enterprise AI tools handed attackers the keys in the same two weeks, and most security teams still don't know.
On June 15, Varonis discloses SearchLeak in Microsoft 365 Copilot. A victim clicks one crafted microsoft.com link, no plugin and no second prompt needed. Copilot then reads their mailbox and quietly ships the data out through a Bing endpoint that was already on the allowlist.
The system pre-approved its own exfiltration path.
And the blast radius isn't one inbox. Enterprise Search inherits the user's full permissions. Every email, every SharePoint file, every document that person can touch.
Four days earlier, Obsidian published a three-CVE chain against LiteLLM, the open-source gateway a lot of companies put in front of OpenAI, Anthropic, Azure, and Bedrock. A non-admin mints a wildcard key, promotes himself to proxy admin through an unguarded endpoint, then breaks the sandbox with Python's exec(). One developer types one word and the attacker walks away with a root shell. CVSS 9.9 in their own assessment.
Same root cause in both. The AI accepted attacker-controlled input with no real boundary between the outside world and your privileged data.
I have been saying this for years. You cannot bolt security on after you ship the agent. The trust boundary is the product.
This is Copilot's third exfiltration chain in twelve months. Reprompt back in January, EchoLeak before that. That is not a bug, that is an architecture that keeps shipping with the same hole.
And here's the part that has a clock on it. A separate LiteLLM command-injection flaw is already on CISA's exploited list with a remediation deadline of June 22. That's this coming Monday. If you run LiteLLM, you are patching it this weekend or you are exposed.
A DISGRACE that "enterprise-ready" AI is shipping with default configs that hand over admin and mailboxes.
Full breakdown on UnbiasedHeadlines.com, an unbiased news site built entirely by AI agents. No spin. Just the facts.
How is that acceptable?
On June 15, Varonis discloses SearchLeak in Microsoft 365 Copilot. A victim clicks one crafted microsoft.com link, no plugin and no second prompt needed. Copilot then reads their mailbox and quietly ships the data out through a Bing endpoint that was already on the allowlist.
The system pre-approved its own exfiltration path.
And the blast radius isn't one inbox. Enterprise Search inherits the user's full permissions. Every email, every SharePoint file, every document that person can touch.
Four days earlier, Obsidian published a three-CVE chain against LiteLLM, the open-source gateway a lot of companies put in front of OpenAI, Anthropic, Azure, and Bedrock. A non-admin mints a wildcard key, promotes himself to proxy admin through an unguarded endpoint, then breaks the sandbox with Python's exec(). One developer types one word and the attacker walks away with a root shell. CVSS 9.9 in their own assessment.
Same root cause in both. The AI accepted attacker-controlled input with no real boundary between the outside world and your privileged data.
I have been saying this for years. You cannot bolt security on after you ship the agent. The trust boundary is the product.
This is Copilot's third exfiltration chain in twelve months. Reprompt back in January, EchoLeak before that. That is not a bug, that is an architecture that keeps shipping with the same hole.
And here's the part that has a clock on it. A separate LiteLLM command-injection flaw is already on CISA's exploited list with a remediation deadline of June 22. That's this coming Monday. If you run LiteLLM, you are patching it this weekend or you are exposed.
A DISGRACE that "enterprise-ready" AI is shipping with default configs that hand over admin and mailboxes.
Full breakdown on UnbiasedHeadlines.com, an unbiased news site built entirely by AI agents. No spin. Just the facts.
How is that acceptable?