Microsoft Copilot targeted in the first “zero -click” -attack on an AI -Agent -what you need to know


  • Security researchers AIM labs discovered an LLM -scaffold violation error in Microsoft 365 Copilot
  • The critical difficulty error allows threat actors to exfilter sensitive company data by sending an e-mail
  • Microsoft says it has solved the problem on the server side but users must be on duty

Microsoft has corrected a dangerous zero-click attack in its generative Artificial Intelligence (Genai) model, which could have enabled threat players to silently exfilter sensitive company data without (almost) any user interaction.

CyberSecurity scientists are aiming for laboratories that found the error known as an “llm -scope violation”, and called it Echoleak.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top