SearchLeak exploit shows why the industry’s approach to LLM security fails over and over. Dan Goodin – Jun 16, 2026 7:15 am | Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible to Copilot.