Microsoft Copilot directed in the first “click zero” attack against an AI agent: what you need to know




  • AIM LABS security researchers discovered a rapid failure of LLM reach in Microsoft 365 Copilot
  • The critical severity error allows threat actors to exfiltrate confilious corporate data by sending an email
  • Microsoft says it has solved the server problem, but users must be on guard

Microsoft has set a dangerous attack with zero click on its generative model of artificial intelligence (Genai) that could have allowed threat actors to silently exfiltrate confidential corporate data without (almost) no user interaction.

Cybersecurity researchers AIM Labs, who found the defect, known as a “violation of the scope of LLM”, and called Echoleak.

Leave a Comment

Your email address will not be published. Required fields are marked *