National Cyber Warfare Foundation (NCWF)

Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction


0 user ratings
2025-06-12 11:57:41
milo
Blue Team (CND)
A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 Copilot's context sans any user interaction.
The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/06/zero-click-ai-vulnerability-exposes.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.