{"id":2024,"date":"2025-06-13T12:15:00","date_gmt":"2025-06-13T09:15:00","guid":{"rendered":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/"},"modified":"2025-06-13T12:15:00","modified_gmt":"2025-06-13T09:15:00","slug":"m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/","title":{"rendered":"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach"},"content":{"rendered":"<p>In a groundbreaking revelation, researchers from Aim Labs have identified a critical zero-click vulnerability in Microsoft 365 Copilot that enables the unauthorized extraction of sensitive corporate data through a basic email. This vulnerability, named \u2018EchoLeak,\u2019 capitalizes on inherent design flaws associated with Retrieval Augmented Generation (RAG) Copilots, allowing attackers to exfiltrate data from M365 Copilot\u2019s context autonomously, without necessitating any specific user interaction.<\/p>\n<p>The discovery was made by the researchers while employing a novel exploitation method termed \u2018Large Language Model (LLM) Scope Violation.\u2019 According to their findings shared in a June 11 report, this marks the first recorded zero-click AI vulnerability.<\/p>\n<p>After identifying the flaw, Aim Labs approached Microsoft in January 2025. Subsequently, the company developed and deployed a patch for the vulnerability by May 2025.<\/p>\n<h3>Understanding Microsoft 365 Copilot&apos;s Utilization of RAG and LLMs<\/h3>\n<p>Microsoft 365 Copilot is an AI-enhanced productivity suite that collaborates with applications such as Word, Excel, PowerPoint, Outlook, and Teams. It leverages LLMs\u2014specifically, OpenAI&#8217;s GPT models\u2014and the Microsoft Graph to tailor responses and provide features like document drafting, email summarization, and presentation generation.<\/p>\n<p>The tool specifically employs RAG techniques, which permit LLMs to retrieve and integrate fresh information. As detailed in the Aim Labs report, \u201cM365 Copilot queries the Microsoft Graph to extract relevant details from the user\u2019s organizational environment, including their mailbox, OneDrive storage, M365 Office files, internal SharePoint sites, and Microsoft Teams chat history.\u201d Although Copilot&#8217;s permission model restricts users to their own files, these files may contain confidential proprietary or compliance-related data.<\/p>\n<h3>LLM Scope Violation<\/h3>\n<p>During their testing, the Aim Labs team implemented a new form of indirect prompt injection (tracked as LLM01 in OWASP\u2019s Top 10 for LLM Applications), identified as \u2018LLM Scope Violation.\u2019 This technique allows an LLM to access sensitive data without the user&#8217;s permission. It comprises several steps in which an attacker circumvents various security protocols to inject harmful prompts into the LLM.<\/p>\n<p>The attack sequence can be broken down as follows:<\/p>\n<p>1. <strong>XPIA Bypass<\/strong>: An attacker sends an email with specific markdown instructions intended to prompt Copilot\u2019s underlying LLM. The message is crafted to suggest that the instructions are directed at the email recipient, successfully evading Microsoft\u2019s cross-prompt injection attack classifiers.<br \/>\n2. <strong>Link Redaction Bypass<\/strong>: The attacker requests sensitive company information from Copilot, attempting to exfiltrate it by embedding it within a markdown link that employs reference-style markdown links, thus evading security measures designed for link redaction.<br \/>\n3. <strong>Image Redaction Bypass<\/strong>: To facilitate automated data extraction without requiring user interaction, attackers endeavor to generate an image that includes sensitive information as a query string parameter appended to the image URL, using reference-style markdown images to bypass image redaction protocols.<br \/>\n4. <strong>CSP Bypass<\/strong>: The browser&#8217;s Content-Security-Policy (CSP) restricts the fetching of images from unauthorized domains, impeding exfiltration via the image URL. Attackers investigate allowed domains within the CSP, notably focusing on SharePoint and Microsoft Teams.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach-1.webp\" alt=\"EchoLeak attack flow\"><\/p>\n<h3>Identifying Common Design Flaws in RAG Applications and AI Agents<\/h3>\n<p>The Aim Labs team has categorized this string of vulnerabilities under the term \u2018EchoLeak,\u2019 blending traditional vulnerabilities with advanced AI-related weaknesses. They conclude, \u201cThis is a novel practical attack on an LLM application that adversaries can weaponize. The attack permits the exfiltration of the most sensitive data from the present LLM context, ensuring that the most confidential information is leaked, independent of specific user actions, and can be conducted in both single-turn and multi-turn interactions.\u201d<\/p>\n<p>Though their primary focus was M365 Copilot, researchers affirm that the vulnerability could also be exploited within other RAG applications and AI agents.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a groundbreaking revelation, researchers from Aim Labs have identified a critical zero-click vulnerability in Microsoft 365 Copilot that enables&#8230;<\/p>\n","protected":false},"author":1,"featured_media":2025,"comment_status":"open","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[885,144,108],"class_list":["post-2024","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-data-extraction","tag-exploitation","tag-vulnerability"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach\" \/>\n<meta property=\"og:description\" content=\"In a groundbreaking revelation, researchers from Aim Labs have identified a critical zero-click vulnerability in Microsoft 365 Copilot that enables...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-13T09:15:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach-1.webp\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/\",\"url\":\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/\",\"name\":\"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp\",\"datePublished\":\"2025-06-13T09:15:00+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp\",\"width\":1792,\"height\":1024,\"caption\":\"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach[:] - Trustcrypt","og_description":"In a groundbreaking revelation, researchers from Aim Labs have identified a critical zero-click vulnerability in Microsoft 365 Copilot that enables...","og_url":"https:\/\/trustcrypt.com\/ar\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/","og_site_name":"Trustcrypt","article_published_time":"2025-06-13T09:15:00+00:00","og_image":[{"url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach-1.webp","type":"","width":"","height":""}],"author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"3 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/","url":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/","name":"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp","datePublished":"2025-06-13T09:15:00+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/m365-copilot-emerging-zero-click-ai-vulnerability-facilitates-corporate-data-breach.webp","width":1792,"height":1024,"caption":"M365 Copilot: Emerging Zero-Click AI Vulnerability Facilitates Corporate Data Breach"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/2024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=2024"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/2024\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/2025"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=2024"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=2024"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=2024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}