Introduction
A critical vulnerability known as EchoLeak has been identified in Microsoft 365 Copilot, allowing unauthorized data exfiltration without user interaction. This zero-click attack exploits the AI's processing of untrusted content, raising significant security concerns. This article delves into the details of the EchoLeak vulnerability, its attack sequence, implications, and related security concerns like tool poisoning and DNS rebinding.