Microsoft Copilot hit by first “zero-click” AI agent attack

Security researchers from Aim Labs uncovered a critical attack dubbed ‘EchoLeak’ impacting Microsoft 365 Copilot. The vulnerability could potentially allow bad actors to gain unauthorized access to sensitive data from Microsoft 365 Copilot users without any interaction.

The security researchers presented their findings to Microsoft, prompting the tech giant to assign the vulnerability the identifier CVE-2025-32711. EchoLeak marks the first known zero-click attack on an AI agent (via Fortune).

Leave a Reply

Your email address will not be published. Required fields are marked *