LogoAgentHunter
  • Submit
  • Industries
  • Categories
  • Agency
Logo
LogoAgentHunter

Discover, Compare, and Leverage the Best AI Agents

Featured On

Featured on yo.directory
yo.directory
Featured on yo.directory
Featured on Startup Fame
Startup Fame
Featured on Startup Fame
AIStage
Listed on AIStage
Sprunkid
Featured on Sprunkid
Featured on Twelve Tools
Twelve Tools
Featured on Twelve Tools
Listed on Turbo0
Turbo0
Listed on Turbo0
Copyright © 2025 All Rights Reserved.
Product
  • AI Agents Directory
  • AI Agent Glossary
  • Industries
  • Categories
Resources
  • AI Agentic Workflows
  • Blog
  • News
  • Submit
  • Coummunity
  • Ebooks
Company
  • About Us
  • Privacy Policy
  • Terms of Service
  • Sitemap
Back to News List

Microsoft Copilot vulnerability EchoLeak enabled zero-click data theft

2025-06-11•David Jones•Original Link•2 minutes
Cybersecurity
Microsoft
AI

Researchers found a critical flaw in Microsoft Copilot that allowed hackers to access sensitive data without user interaction, now patched by Microsoft.

Microsoft CEO Satya Nadella speaks during the OpenAI DevDay event on Nov. 6, 2023, in San Francisco.

Researchers discovered a critical vulnerability in Microsoft's Copilot AI tool that could have allowed attackers to steal sensitive data without any user interaction.

The EchoLeak Vulnerability

  • Dubbed EchoLeak (CVE-2025-32711), the flaw represented the first known zero-click attack on an AI agent.
  • Attackers could exploit an LLM scope violation to commandeer Copilot and access privileged data.
  • Vulnerable data included chat histories, OneDrive documents, Sharepoint content, Teams conversations, and preloaded organizational data.

How It Worked

  • The attack could be triggered simply by sending an email to a target.
  • No user interaction was required, making it particularly dangerous.
  • Default Copilot configurations left most organizations at risk until patched.

Microsoft's Response

  • Microsoft released an advisory confirming the issue was fully addressed.
  • The company implemented updates and additional defense-in-depth measures.
  • "We appreciate Aim Labs for identifying and responsibly reporting this issue," a Microsoft spokesperson said.

Expert Insights

  • Adir Gruss, CTO at Aim Security, called it a "significant breakthrough in AI security research."
  • Jeff Pollard, VP at Forrester, noted the risks align with prior concerns about AI agents: "Attackers will find a way to exploit it given the treasure trove of information."

Key Takeaways

  • The vulnerability highlights the evolving risks of AI-powered tools in enterprise environments.
  • Organizations should ensure they apply the latest patches and review AI agent configurations.
  • Microsoft has confirmed no evidence of customer targeting, but the potential impact was severe.

For more details, read the full report from Aim Security.

Related News

2025-06-16•Daniel Konstantinovic

Microsoft DSP closure reshapes programmatic ad buying landscape

Microsoft's decision to close its DSP Invest marks a shift in programmatic ad buying, reducing Big Tech's role in third-party ad inventory management and opening opportunities for smaller players.

Programmatic
AdTech
Microsoft
2025-06-16•Stephen Withers

Qualtrics AI Copilot Helps Companies Act Faster on Customer Feedback

Qualtrics' new AI tool, Assist for CX, enables organizations to quickly analyze and act on customer feedback, with an Australian airline already cutting insight times from months to hours.

AI
CustomerExperience
Qualtrics

Agent Newsletter

Get Agentic Newsletter Today

Subscribe to our newsletter for the latest news and updates