Microsoft SharePoint, Apple Screen Sharing, and Copilot's Data Leak Problem: The 19 August 2026 Threat Brief

Podcast

Microsoft SharePoint, Apple Screen Sharing, and Copilot's Data Leak Problem: The 19 August 2026 Threat Brief

Three vulnerabilities landed on CISA’s confirmed exploitation list overnight. Two of them require no credentials whatsoever. One of them is sitting in the AI assistant your staff probably use daily.

This is not a theoretical risk assessment. These are confirmed, active attacks.

The Three Stories That Matter Today

There is a lot of noise in the vulnerability feeds right now. Oracle dropped a substantial patch batch yesterday with dozens of critical CVEs across its middleware stack. Most of that is enterprise infrastructure that sits outside the typical UK small business environment.

So let us focus on what is actually relevant.

CVE-2026-55040: Microsoft SharePoint authentication bypass. Added to CISA’s Known Exploited Vulnerabilities catalogue on 18 August. This flaw allows an unauthenticated attacker to bypass SharePoint’s authentication over a network. No credentials needed. If your SharePoint is internet-facing, you have a problem that needs addressing today, not at the next scheduled maintenance window.

CVE-2026-65400: Apple macOS Screen Sharing. Also confirmed as actively exploited on 18 August. An attacker on your local network can authenticate to Screen Sharing without valid credentials. Every unpatched Mac in your office, on your Wi-Fi, or on your VPN is a potential entry point. Apple has released macOS Tahoe 26.6.2 to address this. Check your update status now.

CVE-2026-24301: Microsoft Copilot Personal data exfiltration. Varonis Threat Labs, who dubbed this ‘CoSnitch’, disclosed that a specially crafted link sent to a Copilot user could auto-execute a prompt the moment the page loaded. That prompt could silently pull data from every app Copilot was connected to and exfiltrate it via URL fetches. One click. No warning. Microsoft has patched this, but the patch only protects users who are running the current version.

Why the SharePoint Flaw Deserves Your Immediate Attention

SharePoint is not just enterprise infrastructure. A significant number of UK small businesses use SharePoint as their document store, intranet, and file sharing platform, often managed through a Microsoft 365 subscription.

An authentication bypass means the attacker does not need to steal a password, guess a credential, or social-engineer a staff member. They connect to the service. That is all.

The CISA KEV listing is the unambiguous signal here. CISA only adds vulnerabilities to that list when there is confirmed evidence of active exploitation in the wild. This is not a theoretical proof-of-concept. Someone is using this, right now, against real targets.

If your SharePoint is accessible over the internet, restrict access to known IP ranges or put it behind your VPN immediately while you arrange patching. If your IT support or MSP has not contacted you about this yet, contact them.

Why the Apple Flaw Is a Physical Security Problem

The macOS Screen Sharing vulnerability (CVE-2026-65400) has a specific threat model that is worth understanding clearly.

The attacker needs to be on your network. That sounds like a restriction. It is not as restrictive as it sounds.

Your network includes: your office Wi-Fi, any guest Wi-Fi you run, your VPN, and any network your staff connect to when working remotely if you are routing traffic through a shared gateway. A former employee who still knows the Wi-Fi password. A visitor who connected to the guest network. A compromised device already on the network that is being used as a pivot point.

Screen Sharing on macOS is a remote access tool. An attacker who can authenticate to it without credentials has full visual and interactive control of that machine.

Apple has published updates for iOS, iPadOS, and macOS. The relevant fix for this specific vulnerability is in macOS Tahoe 26.6.2. Check your machines. Update them.

This is not a complicated remediation. It is a software update. The only reason this vulnerability persists in an environment is that the update has not been applied.

What the Copilot Flaw Tells Us About AI Tool Risk

The Copilot Personal vulnerability is now patched, which means the immediate risk has been addressed by Microsoft. But the mechanism is worth understanding, because it will not be the last time we see this class of attack against AI assistants.

The attack worked by exploiting how Copilot handled a specific URL parameter. Varonis researchers found that a crafted link could instruct Copilot to auto-execute an attacker-controlled prompt on page load, without any visible indication to the user. That prompt could then instruct Copilot to fetch data from connected applications, including email, calendar, and any other services the user had linked, and send that data to an attacker-controlled endpoint.

The user’s experience: they clicked a link. That is it.

This is prompt injection delivered via URL. It is not a new class of attack conceptually, but seeing it confirmed and patched in a major commercial AI product used by millions of people is significant.

The practical implication for small businesses: every AI tool your staff use that connects to other services carries a version of this risk. The question to ask is not ‘is this patched right now’ but ‘what data can this tool access, and what happens if someone tricks it into sharing that data.’

For Copilot specifically: ensure your staff are running the current, patched version. Review which applications Copilot is connected to and revoke any connections that are not actively needed.

How to Turn This Into a Competitive Advantage

Every time CISA confirms active exploitation of a vulnerability, there is a window. Organisations that patch within that window are not the ones that end up in breach notifications. Organisations that do not patch are.

If you have a supplier or client relationship with larger organisations, demonstrating that you have a systematic process for monitoring and acting on confirmed active exploits is a meaningful differentiator. Larger organisations are increasingly asking about their supply chain’s security posture. Being able to say ‘we monitor CISA KEV additions and act on them within 24 to 72 hours’ is a concrete, verifiable claim.

Cyber Essentials certification requires that you apply critical security updates within 14 days for internet-facing systems. CISA-confirmed active exploitation is the clearest possible signal that a patch is critical. Getting ahead of the 14-day window is the standard; responding within 24 hours to confirmed active exploitation is what actually demonstrates you take this seriously.

Making the Business Case

Three points for your board or whoever controls the IT budget:

The risk is confirmed, not theoretical. CISA’s Known Exploited Vulnerabilities list only includes vulnerabilities where active exploitation in the real world has been confirmed. These are not hypothetical risks. Attackers are using these techniques against real organisations right now.

The cost of remediation is a software update. Two of these three vulnerabilities are addressed by applying available vendor patches. The cost is time, not budget. The cost of not patching is measured in incident response, regulatory notification under UK GDPR, and business disruption.

The Copilot issue points to a broader governance question. How many AI tools are your staff using? What data can those tools access? Do you have a policy governing AI tool use that includes data connection hygiene? If the answer to any of those is ‘I am not sure’, that is the conversation to have.

What to Do Before the End of the Week

  1. Patch or restrict SharePoint immediately. If you use Microsoft 365 SharePoint and it is accessible over the internet, apply Microsoft’s patch or restrict network access to authorised IP ranges while you arrange patching. If you use a managed Microsoft 365 service, contact your provider today and ask specifically about CVE-2026-55040.

  2. Update every Mac in your environment. Go to System Settings, General, Software Update on each macOS device. You are looking for macOS Tahoe 26.6.2 or later. This applies to any Mac used for business purposes, including staff personal devices used for work. If you have remote workers, send the instruction now.

  3. Verify Copilot version and review connected apps. If your staff use Microsoft Copilot Personal, confirm they are running the current patched version. Then go into Copilot’s connected apps settings and revoke any connections to services that are not actively needed.

  4. Check your MSP’s response. If you pay a managed service provider to look after your IT, ask them specifically what they have done in response to the 18 August CISA KEV additions. If they cannot answer clearly, that is a performance issue worth noting.

  5. Log this. If you are working toward Cyber Essentials or any other certification, document the date you identified these vulnerabilities, the date you applied mitigations, and the actions taken. That record demonstrates your process is functioning.

Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this episode with someone who would find it useful. The more people who act on this information, the fewer UK small businesses end up in a breach notification.

SourceArticle
CISAKnown Exploited Vulnerabilities Catalogue: CVE-2026-55040, CVE-2026-65400
Microsoft Security Response CentreCVE-2026-24301: Microsoft Copilot Personal Information Disclosure Vulnerability
The Hacker NewsMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Apple SupportmacOS Tahoe 26.6.2 Security Updates
NIST NVDCVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability
NIST NVDCVE-2026-65400: Apple macOS Improper Authentication Vulnerability
Varonis Threat LabsCoSnitch: Microsoft Copilot Personal Vulnerability Research

Filed under

  • smb-security
  • uk-business
  • credential-theft
  • cloud-security
  • remote-access
  • business-risk
  • incident-response