Opening EchoLeak — zero-click prompt injection in Microsoft 365 Copilot on Rogue Agent Watch.
Confirmed · Primary sourcing · AI load-bearing · Critical severity.
Aim Labs (Aim Security) disclosed EchoLeak, assigned CVE-2025-32711, a zero-click indirect prompt-injection vulnerability in Microsoft 365 Copilot. A single crafted email could cause the retrieval-augmented Copilot agent to pull sensitive organisational data from the user's context and exfiltrate it with no user interaction. Aim Labs termed the underlying class "LLM Scope Violation." Microsoft patched it server-side and states no customers were affected.
Data: Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, CC BY-SA 4.0.