Researchers find ‘dangerous’ AI data leak flaw in Microsoft 365 Copilot: What the company has to say

A critical artificial intelligence (AI) vulnerability has been discovered in Microsoft 365 Copilot, raising new concerns about data security in AI-integrated enterprise environments. The flaw, dubbed ‘EchoLeak’, which enabled attackers to exfiltrate sensitive user data with zero-click interaction, has been devised by Aim Labs researchers in January 2025.

According to a report by Bleeping Computer, Aim Labs promptly reported their findings to Microsoft, which rated it as critical. Microsoft swiftly addressed the issue, implementing a server-side fix in May 2025.

Read more

You may also like

Comments are closed.

More in IT