Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
ID: 4f82cc81-25df-5ab4-9582-4f4cd889ffd9
STIX ID: report--4f82cc81-25df-5ab4-9582-4f4cd889ffd9
Feed Name: Cato Networks
## Executive Summary Aim Labs disclosed "EchoLeak", a zero-click vulnerability chain against Microsoft 365 Copilot that leverages an "LLM Scope Violation" to cause the model to access and exfiltrate privileged organizational context without user interaction; the research details bypasses of XPIA prompt-injection classifiers, markdown link/image redaction, and Content-Security-Policy (using SharePoint/Teams redirect primitives), describes weaponization techniques (RAG spraying and crafted instructions), and reports the issue to Microsoft with no known customer impact to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
