Close Menu
GT NewsGT News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Security heightened for Fourth of July events amid Iran tensions, expert warns

    July 1, 2025

    Gold up Rs108,500 in FY25

    July 1, 2025

    Football: Players’ body wants half-time breaks to be 20 minutes | Football News

    July 1, 2025
    Facebook X (Twitter) Instagram
    GT NewsGT News
    • Home
    • Trends
    • U.S
    • World
    • Business
    • Technology
    • Entertainment
    • Sports
    • Science
    • Health
    GT NewsGT News
    Home » Microsoft fixes first known zero-click attack on an AI agent
    Technology

    Microsoft fixes first known zero-click attack on an AI agent

    LuckyBy LuckyJune 12, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft fixes first known zero-click attack on an AI agent
    Share
    Facebook Twitter LinkedIn Pinterest Email

    TL;DR: Microsoft has patched a critical zero-click vulnerability in Copilot that allowed remote attackers to automatically exfiltrate sensitive user data simply by sending an email. Dubbed “EchoLeak,” the security flaw is being described by cybersecurity researchers as the first known zero-click attack targeting an AI assistant.

    EchoLeak affected Microsoft 365 Copilot, the AI assistant integrated across several Office applications, including Word, Excel, Outlook, PowerPoint, and Teams. According to researchers at Aim Security, who discovered the vulnerability, the exploit allowed attackers to access sensitive information from apps and data sources connected to Copilot without any user interaction.

    Alarmingly, the malicious email did not contain any phishing links or malware attachments. Instead, the attack leveraged a novel technique known as LLM Scope Violation, which manipulates the internal logic of large language models to turn the AI agent against itself.

    Researchers warn that this approach could be used to compromise other Retrieval-Augmented Generation chatbots and AI agents in the future. Because it targets fundamental design flaws in how these systems manage context and data access, even advanced platforms such as Anthropic’s Model Context Protocol and Salesforce’s Agentforce could be vulnerable.

    Aim Security discovered the flaw in January and promptly reported it to the Microsoft Security Response Center. However, the company took nearly five months to resolve the issue, a timeline that co-founder and CTO Adir Gruss described as on the “very high side of something like this.”

    Microsoft reportedly had a hotfix ready by April, but the patch was delayed after engineers uncovered additional vulnerabilities in May. The company initially attempted to contain EchoLeak by blocking its pathways across affected apps, but those efforts failed due to the unpredictable behavior of AI and the vast attack surface it presents.

    Following the final update, Microsoft issued a statement thanking Aim Security for responsibly disclosing the issue and confirmed that it had been fully mitigated. The fix was automatically applied to all impacted products and requires no action from end users.

    Although there are no known cases of EchoLeak being exploited in the wild, many Fortune 500 companies are reportedly “super afraid” and now re-evaluating their strategies for deploying AI agents across enterprise environments. According to Gruss, the industry needs to implement robust guardrails to prevent similar incidents in the future.

    In the meantime, Aim Security is providing interim mitigations to clients using AI agents potentially vulnerable to the same class of attack. But Gruss believes a long-term solution will require a fundamental redesign of how AI agents are built and deployed.

    Agent attack Fixes Microsoft zeroclick
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleClosing arguments set for Friday in Karen Read’s second trial over cop’s death
    Next Article How to manage arthritis flare-ups this summer
    Lucky
    • Website

    Related Posts

    Health

    Can swallowing a bee cause a heart attack? Experts comment on rare case

    June 30, 2025
    Entertainment

    Iraqi security personnel hurt in rocket attack on Kirkuk base

    June 30, 2025
    World

    82-year-old woman dies from Boulder terror attack injuries

    June 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Stability trend for private markets to see in 2025

    February 21, 2025971 Views

    Appeals court allows Trump to enforce ban on DEI programs for now

    March 14, 2025943 Views

    My mom says these Sony headphones (down to $38) are the best gift I’ve given her

    February 21, 2025886 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    • Pinterest
    • Reddit
    • Telegram
    • Tumblr
    • Threads
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Stability trend for private markets to see in 2025

    February 21, 2025971 Views

    Appeals court allows Trump to enforce ban on DEI programs for now

    March 14, 2025943 Views

    My mom says these Sony headphones (down to $38) are the best gift I’ve given her

    February 21, 2025886 Views
    Our Picks

    Security heightened for Fourth of July events amid Iran tensions, expert warns

    July 1, 2025

    Gold up Rs108,500 in FY25

    July 1, 2025

    Football: Players’ body wants half-time breaks to be 20 minutes | Football News

    July 1, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube Tumblr Reddit Telegram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © .2025 gtnews.site Designed by Pro

    Type above and press Enter to search. Press Esc to cancel.