A critical Copilot vulnerability called SearchLeak could allow attackers to steal two-factor authentication codes, Ars Technica reports. The exploit highlights how LLM-connected search and assistant features can create unexpected data-exposure paths.

The incident matters because AI assistants are increasingly wired into email, documents, browsers, and workplace tools. When those systems retrieve and summarize private data, security boundaries can become harder to reason about.

For AI product teams, the lesson is familiar but urgent: prompt safety is not enough. Retrieval permissions, isolation, logging, and adversarial testing need to be treated as core security controls.