Security researchers at Aim Security disclosed “EchoLeak” (CVE-2025-32711), a critical zero-click vulnerability in Microsoft 365 Copilot that let a single specially crafted email manipulate the AI assistant into automatically exfiltrating sensitive inbox, OneDrive, SharePoint, and Teams content to an attacker-controlled server, without any user interaction. Microsoft patched the flaw server-side and found no evidence it had been exploited in the wild before disclosure.