Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

EchoLeak: zero-click prompt injection in Microsoft 365 Copilot

Researchers at Aim Security found that a crafted email could make Microsoft 365 Copilot exfiltrate data from a user's tenant with no clicks, tracked as CVE-2025-32711.

Occurred 15 January 2025 · Disclosed 11 June 2025 · Record updated 13 September 2026

Impact

Sensitive data reachable by Copilot (emails, files, chats) could be exfiltrated by any external sender. Microsoft patched server-side before disclosure; no customer action was required.

Our coverage

Sources

  1. aim.securityhttps://www.aim.security/lp/aim-labs-echoleak-blogpost
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-32711
  3. msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711