Microsoft Fixes Zero-Click Vulnerability in Copilot AI
Microsoft Corporation has resolved a critical security flaw in its Copilot AI system, identified by Aim Security, a Tel Aviv-based cybersecurity firm. The vulnerability, known as EchoLeak, was characterized as a 'zero-click' flaw, meaning it could be exploited without any user interaction, according to Inc.
The EchoLeak vulnerability, assigned the identifier CVE-2025-32711, allowed unauthorized access to sensitive data within Microsoft 365 Copilot's context. This flaw was particularly dangerous as it enabled attackers to exfiltrate data without user awareness or action. The attack involved embedding malicious prompts in seemingly benign content, such as emails, which the AI system would process, leading to unintended data leaks.
Microsoft has already addressed the issue server-side, ensuring that no customer action is required. The company confirmed that there was no evidence of the vulnerability being exploited in the wild. This incident highlights the potential risks associated with AI systems and the importance of ongoing vigilance in cybersecurity measures.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 16 AV-Comparatives Certifies 11 Endpoint Security Products in 2026 Test Sep 16 Cohesity Adds AI Agent Backup and Recovery to Data Cloud Sep 15 Hexnode Introduces Synapse for IT and Security Operations Sep 15 Cisco Expands Splunk AI for Private and Isolated Environments Sep 15 Zip Security Joins CrowdStrike Coalition to Protect Small BusinessesCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Whitepaper
Tensordyne Napier: What If One Rack Could Do the Work of Nine?
Tensordyne
This Tensordyne whitepaper presents Napier, an inference-focused AI processor and rack-scale system based on the company’s TDN Math logarithmic number system. It examines infrastructure requirements for large mixture-of-experts and agentic models, compares major inference architecture approaches, and details the TDN AIP processor, TDN72 pod, TDN Link fabric, and Napier Ultra configuration. The paper reports simulation-based performance, cost, and accuracy-validation results, including Tensordyne’s projected comparison of one Napier rack with a nine-rack Nvidia Rubin plus Groq deployment; the chip is reported as taped out and in fabrication.
Read moreYou may also like
Cypris Adds R&D Agents to Microsoft Copilot
OpenAI Executive Warns of Persistent AI Cyber Attacks
Palo Alto Networks Introduces Critical Infrastructure Defense Program
Quandary Peak Adds CogniCrypt Malware Detection to M&A Due Diligence
Microsoft and Teacher Unions Create AI Privacy Standard for US Schools
Daily AI Brief: the AI news that matters, in your inbox.