Microsoft Copilot targeted in the first attack “zero click on an AI agent – what you need to know


  • AIM Labs safety researchers discovered a lack of violation of the LLM scope in Microsoft 365 COPILOT
  • The critical severity bug allows threats to exfiltrate sensitive business data by sending an email
  • Microsoft says he has solved the server problem, but users should be on the guard

Microsoft has set a dangerous zero attack click in its model generator of artificial intelligence (GENAI) which could have allowed the actors to threaten to silently exfiltrate sensitive business data without (almost) no user interaction.

Cybersecurity researchers target laboratories, which found the defect, known as “violation of the range of the LLM”, and nicknamed Echoleak.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top