AI Security
EchoLeak (CVE-2025-32711): The First Zero-Click LLM Exfiltration in Production
Aim Security's CVE-2025-32711 exfiltrated Microsoft 365 Copilot data via a single crafted email. The XPIA classifier failed, CSP let attackers through, and CVSS 9.3 followed.
Jun 24, 20256 min read