Critical Security Flaw in Microsoft 365 Copilot Raises Zero-Click Attack Concerns

1 min read
Source: BleepingComputer
Critical Security Flaw in Microsoft 365 Copilot Raises Zero-Click Attack Concerns
Photo: BleepingComputer
TL;DR

Researchers uncovered 'EchoLeak,' a critical zero-click vulnerability in Microsoft 365 Copilot that allows silent exfiltration of sensitive data through prompt injection, highlighting emerging risks in AI-integrated enterprise systems. Microsoft fixed the flaw in May, with no evidence of exploitation, but the attack demonstrates the need for enhanced defenses against LLM scope violations.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer