9 Sources
[1]
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user's context without interaction. The attack was devised by Aim Labs researchers in January 2025, who reported their findings to
[2]
Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction
A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 Copilot's context sans any user interaction. The critical-rated vulnerability has been assigned the CVE
[3]
Microsoft fixes first known zero-click attack on an AI agent
TL;DR: Microsoft has patched a critical zero-click vulnerability in Copilot that allowed remote attackers to automatically exfiltrate sensitive user data simply by sending an email. Dubbed "EchoLeak," the security flaw is being described by cybersecurity researchers as the first known zero-click
[4]
Microsoft Copilot targeted in first "zero-click" attack on an AI agent - what you need to know
Microsoft says it has fixed the issue server-side, but users should be on guard Microsoft has fixed a dangerous zero-click attack in its Generative Artificial Intelligence (GenAI) model which could have allowed threat actors to silently exfiltrate sensitive corporate data without (almost) any user
[5]
Aim Security details first known AI zero-click exploit targeting Microsoft 365 Copilot - SiliconANGLE
Aim Security details first known AI zero-click exploit targeting Microsoft 365 Copilot A new report out today from Aim Security Ltd. has revealed the first known zero-click artificial intelligence vulnerability that could have allowed attackers to exfiltrate sensitive internal data without any
[6]
Researchers Just Found a Big Security Flaw in Microsoft's AI. Here's Why Businesses Should Worry
The type of security flaw found in Copilot is particularly dangerous because it means a user doesn't have to make a deliberate action to trigger the flaw to allow a hacker into a system. Most people are familiar with simpler types of hacks that rely on someone clicking on a phishing email, or
[7]
Microsoft 365 Copilot Could Be Hacked Without Any User Input: Research
This is said to be the first zero-click exploit on a major AI chatbot Microsoft 365 Copilot, the enterprise-focused artificial intelligence (AI) chatbot that works across Office apps, was reportedly vulnerable to a zero-click vulnerability. As per a cybersecurity firm, a flaw existed in the
[8]
Hackers Could Steal Data From Microsoft 365 Copilot Without Phishing Or Malware, Says AI Startup -- 'EchoLeak' Flaw Took 5 Months To Fix - Alphabet (NASDAQ:GOOG), Alphabet (NASDAQ:GOOGL)
A critical security flaw was discovered in Microsoft MSFT 365 Copilot, an AI tool integrated into various Microsoft Office applications. This vulnerability could potentially lead to attacks on sensitive data. What Happened: The security flaw in Microsoft 365 Copilot was identified by AI security
[9]
Hackers successfully attacked an AI agent, Microsoft fixed the flaw: Here's why it's scary
Fortune's report on EchoLeak reveals how Microsoft's Copilot could be tricked into exposing internal data. It didn't start with a ransom note, there were no system crashes, no screens held hostage. Just an AI assistant, Microsoft Copilot, doing exactly what it was designed to do: be helpful. And
Share
Copy Link
Researchers uncover a critical zero-click AI vulnerability in Microsoft 365 Copilot, allowing attackers to exfiltrate sensitive data without user interaction. The flaw, dubbed "EchoLeak," highlights new security risks in AI-integrated systems.
In a groundbreaking discovery, researchers at Aim Labs have uncovered the first known zero-click artificial intelligence (AI) vulnerability, dubbed "EchoLeak." This critical flaw, identified in January 2025, affects Microsoft 365 Copilot, an AI assistant integrated into various Office applications
1
.EchoLeak is classified as an "LLM Scope Violation," a new class of vulnerabilities that can cause large language models (LLMs) to leak privileged internal data without user intent or interaction
2
. The attack exploits the Retrieval-Augmented Generation (RAG) engine used by Copilot, allowing attackers to exfiltrate sensitive information from a user's context silently.
Source: BleepingComputer
The attack begins with a malicious email containing a hidden prompt injection, crafted to instruct the LLM to extract and exfiltrate sensitive internal data. This email, formatted to look like a typical business document, bypasses Microsoft's XPIA (cross-prompt injection attack) classifier protections
1
.When a user later interacts with Copilot, the RAG engine retrieves the malicious email due to its apparent relevance. The injected prompt then "tricks" the LLM into pulling sensitive data and inserting it into a crafted link or image
3
.
Source: Hacker News
Aim Labs discovered that certain markdown image formats cause the browser to automatically request the image, sending the URL (including embedded data) to the attacker's server. While Microsoft's Content Security Policy (CSP) blocks most external domains, Microsoft Teams and SharePoint URLs are trusted and can be abused to exfiltrate data without issue
1
.Microsoft assigned the vulnerability the identifier CVE-2025-32711, rating it critical with a CVSS score of 9.3 out of 10
4
. The company addressed the issue server-side in May 2025, requiring no action from users. Microsoft stated that there is no evidence of real-world exploitation, and no customers were impacted2
.Related Stories
The discovery of EchoLeak has significant implications for AI security, particularly for NATO, government, defense, healthcare, and enterprises using AI assistants. Ensar Seker, CISO at SOCRadar, warns that "attackers no longer need to compromise user credentials or rely on phishing. They can manipulate a trusted AI interface directly"
5
.
Source: Benzinga
As AI integration deepens in business workflows, experts warn that traditional defenses may be overwhelmed. Tim Erlin, a security strategist at Wallarm, noted that such vulnerabilities were "bound to happen" given the expanding AI attack surface
5
.To mitigate similar risks, enterprises are advised to:
The EchoLeak vulnerability serves as a wake-up call for the AI industry, highlighting the need for robust security measures in AI-integrated systems. As AI assistants become more prevalent, addressing these vulnerabilities will be crucial to maintain trust and security in AI technologies.
Summarized by
Navi
[1]
[2]
[4]
15 Jun 2026•Technology

18 Aug 2026•Technology

16 Jan 2026•Technology

1
Science and Research

2
Policy and Regulation

3
Technology