Tuesday , June 23 2026
Microsoft 365 Copilot

3 Critical Microsoft 365 Copilot flaws Expose sensitive Information

Microsoft fixed 3 critical security issues in Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. These were released on May 7, 2026, and users or admins don’t need to do anything.

Microsoft’s Security Response Center shared updates on CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 to show their ongoing promise of openness in their cloud services.

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
CISA: Splunk flaw under active exploit, patch by Sunday

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
Texas data breach exposes 3 million driver’s licenses

Microsoft has fixed all three issues completely, following its cloud CVE transparency plan in the “Toward Greater Transparency: Unveiling Cloud Service CVEs” program.

Microsoft 365 Copilot Vulnerabilities

CVE-2026-26129 impacts Microsoft 365 Copilot’s Business Chat. The problem comes from not properly handling special characters in the output, which could let an attacker reveal sensitive information on a network.

CVE-2026-26164 affects M365 Copilot and falls under CWE-74 (Bad Handling of Special Elements in Output Used by Another Part — Injection).

The attack comes from the network, does not need special access or user actions, and has a big effect on confidentiality. The chance of it being exploited is rated as “Exploitation Less Likely,” and the readiness of the exploit code is marked as untested.

CVE-2026-33111 impacts Copilot Chat in Microsoft Edge and is categorized as CWE-77 (Improper Control of Special Elements in a Command — Command Injection).

It has the same CVSS score of 7.5 / 6.5 (temporal) as CVE-2026-26164. It also has the same attack type: it can be accessed through a network, does not need special permissions, does not require user actions, and has a big impact on confidentiality.

Microsoft thanked Estevam Arantes of Microsoft for finding both CVE-2026-26129 and CVE-2026-26164. They also gave credit to independent researcher 0xSombra for CVE-2026-26164.

Microsoft has put fixes in place at the service level. Companies do not have to install updates or change settings.

Security teams should check Copilot’s data access permissions and apply least-privilege rules to lower the risk of similar problems in the future.

Check Also

F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let …