Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction

A novel attack technique named EchoLeak has been characterized as a “zero-click” artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 Copilot’s context sans any user interaction.
The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Non-Human Identities: How to Address the Expanding Security Risk

Next Post

New TokenBreak Attack Bypasses AI Moderation with Single-Character Text Changes

Related Posts
Total
0
Share