Severity

critical

Exposure

5/5

Date of incident

June 11, 2025
Microsoft Copilot EchoLeak

confirmed

Tier -

A

Zero-click injection exfiltrated Copilot session — no tool egress boundary.
What Happened

Attacker sent crafted email with hidden instructions; M365 Copilot processed context and exfiltrated sensitive session data via zero-click indirect prompt injection — Microsoft patched CVE-2025-32711 server-side.

Sumarry

Aim Security disclosed EchoLeak — zero-click indirect prompt injection in Microsoft 365 Copilot (CVE-2025-32711); Microsoft patched server-side.

Detect

Lineage contamination + exfil tool deny after untrusted ingest

What Happened

Agent boundary on Copilot tool egress

Blekline //

Lineage block + tool policy on Copilot connectors

Without agent boundary //

Await vendor patch — no customer-controlled execution hop

Financial services AI security use case

Looking to integrate AI company-wide?