News

Security researchers uncovered “EchoLeak,” a zero-click flaw in Microsoft 365 Copilot, exposing sensitive data without user ...
Security researchers Aim Labs discovered an LLM Scope Violation flaw in Microsoft 365 Copilot The critical-severity bug ...
Aim Labs recently shared findings about the first-ever zero-click AI attack impacting Microsoft 365 Copilot, though there's ...
A single email can silently trigger Copilot to exfiltrate sensitive corporate data — no clicks, no warnings, no user action.
Researchers have found a flaw in Microsoft 365 Copilot that allows the exfiltration of sensitive corporate data with a simple ...
Microsoft recently patched CVE-2025-32711, a vulnerability that could have been used for zero-click attacks to steal data ...
Researchers said the vulnerability, dubbed “EchoLeak,” could allow a hacker to access data without any specific user ...
EchoLeak affected Microsoft 365 Copilot, the AI assistant integrated across several Office applications, including Word, ...
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user's context without interaction.
Security researchers at Aim Security discovered "EchoLeak", the first known zero-click artificial intelligence (AI) ...
Echoleak is a new attack vector that exploits AI assistants by subtly manipulating prompts. The attack was executed without ...
Researchers have said that Microsoft Copilot had a critical zero-click AI vulnerability that was fixed before hackers stole ...