News
Security researchers uncovered “EchoLeak,” a zero-click flaw in Microsoft 365 Copilot, exposing sensitive data without user action. Microsoft has mitigated the vulnerability.
Hosted on MSN24d
Microsoft Copilot's own default configuration exposed users to the first-ever "zero-click" AI attack, but there was no data breachEchoLeak marks the first known zero-click attack on an AI agent (via Fortune). The cybersecurity firm presented its findings to Microsoft earlier this year in January.
The vulnerability, called “EchoLeak,” lets attackers “automatically exfiltrate sensitive and proprietary information” from Microsoft 365 Copilot without knowledge of the user, according to findings ...
The researchers at Aim Security dubbed the flaw “EchoLeak.” Microsoft told Fortune that it has already fixed the issue in Microsoft 365 Copilot and that its customers were unaffected.
Echoes beyond Microsoft “EchoLeak marks a shift to assumption-of-compromise architectures,” Garg stated. “Enterprises must now assume adversarial prompt injection will occur, making real ...
EchoLeak affected Microsoft 365 Copilot, the AI assistant integrated across several Office applications, including Word, Excel, Outlook, PowerPoint, and Teams. According to researchers at Aim ...
What This Vulnerability Teaches Us About AI SecurityThe recent disclosure of EchoLeak by Aim Labs marks a significant milestone in AI security research. As the first documented zero-click exploit ...
Microsoft has already completed its response to Echoleak, but Aim Security CTO Adir Glass pointed out that 'Echoleak can be applied to any type of AI agent, from MCP-compatible services to ...
The vulnerability, dubbed EchoLeak and assigned the identifier CVE-2025-32711, could have allowed hackers to mount an attack without the target user having to do anything.EchoLeak represents the ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results