News

Security researchers Aim Labs discovered an LLM Scope Violation flaw in Microsoft 365 Copilot The critical-severity bug ...
A single email can silently trigger Copilot to exfiltrate sensitive corporate data — no clicks, no warnings, no user action.
Security researchers at Aim Security discovered "EchoLeak", the first known zero-click artificial intelligence (AI) vulnerability in Microsoft 365 Copilot ...
Microsoft is preparing a version of its Copilot AI tool for the Pentagon as it nears a deal to add 1 million new users from a ...
Chief Commercial Officer Judson Althoff told employees in a recent meeting that the software giant is working on this big ...
Microsoft recently patched CVE-2025-32711, a vulnerability that could have been used for zero-click attacks to steal data ...
Microsoft 365 Copilot, the AI tool built into Microsoft Office workplace applications including Word, Excel, Outlook, ...
The M365 AI agent could be tricked into releasing sensitive information via email and without a mouse click. Microsoft has ...
For example, Copilot being able to connect to OneDrive and retrieving data from a file stored there to answer a user query would be considered an agentic action. As per the researchers, the attack was ...
Critically, according to Aim’s researchers, all of this happens behind the scenes. Users themselves don’t have to open the ...
Microsoft is developing a special version of its Copilot AI tool for the Pentagon, tailoring its main AI offering for the US ...
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive ...