What happened
Varonis researchers crafted a URL with a malicious instruction in the Copilot Enterprise Search q parameter telling Copilot to search the victim's mailbox and embed the results in an img tag URL. When a victim clicked the link, Bing's SSRF proxy forwarded the data to attacker infrastructure — all while Copilot appeared to process a normal search.