Echoleak Attack Exposes AI Assistant Vulnerabilities Without Malware
Echoleak is a new attack vector targeting AI assistants like Microsoft 365 Copilot through prompt manipulation, bypassing traditional security measures without malware or phishing.
Researchers at Check Point have uncovered a new zero-click attack vector called Echoleak, which exploits AI assistants like Microsoft 365 Copilot through subtle prompt manipulation—no malware or phishing required. The attack marks a significant shift in cybersecurity threats, as it relies solely on language as a weapon.
How the Attack Works
- The attack injects malicious prompts into seemingly innocent documents or emails.
- Copilot interprets these prompts as commands, not data, leading to unauthorized disclosure of sensitive information (e.g., internal files, emails, or credentials).
- No user interaction is needed; the attack executes automatically.
Obedience as a Weakness
Large Language Model (LLM)-based AI assistants are designed to follow instructions, even when ambiguous. Their deep integration with operating systems and productivity tools creates a dangerous combination: a highly obedient tool with access to critical data.
"The attack vector has shifted from code to conversation," says Check Point. "We’ve built systems that actively convert language into actions. That changes everything."
Limitations of Current Safeguards
Many companies rely on LLM "watchdogs" to filter harmful instructions, but these models are vulnerable to the same deception. Attackers can:
- Spread malicious intent across multiple prompts.
- Hide instructions in other languages.
- Exploit contextual gaps in safeguards (as seen with Echoleak).
Tip: Microsoft turns GitHub Copilot into a full-fledged AI agent
This discovery underscores the urgent need for robust defenses against AI-driven social engineering attacks.
Related News
Microsoft DSP closure reshapes programmatic ad buying landscape
Microsoft's decision to close its DSP Invest marks a shift in programmatic ad buying, reducing Big Tech's role in third-party ad inventory management and opening opportunities for smaller players.
Qualtrics AI Copilot Helps Companies Act Faster on Customer Feedback
Qualtrics' new AI tool, Assist for CX, enables organizations to quickly analyze and act on customer feedback, with an Australian airline already cutting insight times from months to hours.