Microsoft 365 Copilot
Zero-click indirect injection (EchoLeak)
Aim Security found that the victim only had to receive an email. Copilot pulled it into RAG context and executed the embedded instructions without anyone opening it.
Corporate data exfiltrated across Word, Excel, PowerPoint, Outlook and Teams. The exploit bypassed Microsoft's XPIA classifier, link redaction and the Content Security Policy by routing through the allowlisted Teams image proxy.
Suite category