CVE-2025-32711 · Microsoft 365 Copilot
EchoLeak: zero-click prompt injection
A crafted email triggered data exfiltration from Microsoft 365 Copilot without any user interaction — bypassing traditional defenses by leveraging content the AI automatically processed.