GitHub - vikasudasi/exfil-scan: Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems · GitHub https://github.com/vikasudasi/exfil-scan
Post summary
The GitHub repo introduces a scanner to detect data exfiltration signals in LLM outputs and references CVE‑2025‑32711, but provides no additional technical or exploit details.
If enterprises are going to scale Ai, it’s about more than cutting costs and smarter LLM’s.
Security has to be the Top Priority.
In 2025, researchers revealed EchoLeak (CVE-2025-32711) — the first real-world zero-click prompt injection in Microsoft 365 Copilot.
An attacker simply sent a crafted email. No clicks. No interaction.
Copilot ingested the hidden malicious instructions as “trusted” context, bypassed safeguards, pulled sensitive internal data (emails, docs, chats), and exfiltrated it via sneaky auto-fetched image links. Critical severity. Enterprise data at risk.
This wasn’t a one-off — it highlighted how indirect prompt injections turn helpful AI into data leaks waiting to happen.
OWASP still ranks it #1 LLM risk.
Enter @openservai’s Prompt Guard — the fix production agents actually need.
Built into $SERV by default:
• 3 layers of defense against injections
• Battle-tested on 256 attack vectors → zero leaks, zero false positives
Security isn’t an afterthought anymore. It’s infrastructure.
If you’re building or running AI agents, this is how you stop the next EchoLeak before it hits.
Big ups to the @openservai team for shipping real protection.
What’s your biggest AI security worry right now? 👇
#AISecurity#PromptInjection#EchoLeak#OpenServ#SERV
Post summary
EchoLeak CVE-2025-32711 is a real-world zero-click prompt injection in Microsoft 365 Copilot that has been actively exploited; the post highlights a mitigation via @openservai’s Prompt Guard.
The cleanest proof of this is EchoLeak — CVE-2025-32711, CVSS 9.3. One crafted email, zero clicks, and M365 Copilot read your private docs and shipped them out through an invisible image URL it rendered itself. Simon's right that it's structural, not a bug you patch: hold any two legs and you're safe, but no real team gives up private data, inbound content, or outbound calls. Which leaves exactly one leg you can actually cut — gate the action before the model acts, don't trust the model to police its own exfil.
Post summary
The text illustrates a live, zero‑click exploitation of CVE‑2025‑32711 via a crafted email that forces M365 Copilot to exfiltrate private documents, while also suggesting mitigation by gating model actions.
Least privilege caps the blast radius, it doesn't stop the injection. EchoLeak (CVE-2025-32711) was the proof of that — one crafted email, zero clicks, and M365 Copilot shipped internal data out using tools it was *supposed* to have. Nothing was over-privileged. The real fix isn't fewer tools, it's treating untrusted input as tainted and gating the outbound action before it fires — Simon Willison's lethal trifecta: private data + untrusted content + a way to phone home. Kill any one leg and the exfil pipeline dies.
Post summary
The text reports a real-world exploitation of CVE-2025-32711 via a crafted email that caused M365 Copilot to exfiltrate data, highlighting the need for better input validation before outbound actions.
The post details the discovery of CVE‑2026‑26133, a prompt‑injection flaw in Microsoft 365 Copilot’s email summarization, and announces that Microsoft has released a patch for the vulnerability.
Attack in the wild - EchoLeak (CVE-2025-32711) changed the way I look at email security.
The attacker didn't need the employee to click a malicious link. The target was the AI reading the employee's email.
A crafted email could poison the context retrieved by Microsoft 365 Copilot, bypass prompt-injection protections and abuse trusted mechanisms to leak information — with no user click.
That is the bigger lesson from EchoLeak.
As AI becomes an interface to email, documents and enterprise data, we need to secure not only what a user can access, but also what AI can retrieve, trust and act upon.
My minimum controls:
→ Detect prompt injection at email ingress
→ Treat every retrieved document as untrusted input
→ Enforce permission-aware RAG and least privilege
→ Apply DLP to sensitive content accessible to AI
→ Control outbound/remote content retrieval
→ Log prompts, retrieved sources and agent/tool activity
→ Monitor abnormal AI-driven egress
→ Red-team indirect prompt injection continuously
The attack surface is changing.
Yesterday we asked: "Will the user click it?"
Tomorrow we may need to ask: "Will the AI trust it?"
#AISecurity#CyberSecurity#GenAI#CISO#ThreatIntel#PromptInjection
Post summary
EchoLeak CVE-2025-32711 is being actively exploited via prompt‑injection in Microsoft 365 Copilot, bypassing protections without user interaction; no PoC or patch is offered, but the text advises mitigation controls.
I’ve seen numerous failures of trying to secure AI agents with existing SDLC.
An agent plans, remembers, calls tools, and acts on live systems. It reads documents written by attackers (EchoLeak, CVE-2025-32711, zero-click data exfil from M365 Copilot). It loads packages from poisoned registries (LiteLLM PyPI supply chain attack, March 2026, three hours live, ~95M monthly downloads downstream). It connects through protocols that assume localhost is safe (ClawJacked, CVE-2026-25253, ~40,000 OpenClaw agents exposed). And sometimes it finds reward shortcuts on its own (Alibaba ROME mining crypto and opening reverse SSH during RL training).
DLP, SIEM, signature-based EDR don't see most of this. Agents use legitimate credentials, authorized endpoints, and normal HTTP.
I’ve created A.G.E.N.T. as a free pre-deployment checklist for CISOs and Chief AI Officers. Five dimensions, one decision.
A: Access Scope. What systems, data, and tools the agent reaches. If the answer is "the usual developer setup," you failed.
G: Governance Model. Name a person, a team, an on-call rotation. The Meta rogue agent in March 2026 had no clear owner. Two hours of unauthorized data exposure, SEV1.
E: Execution Authority. Autonomous reads on non-sensitive data. Gated writes. Human approval required on destructive operations. A Claude Code agent ran terraform destroy on a "clean up the environment" instruction in February 2026. 100,000 students lost 2.5 years of work. Human-approval gates are cheap.
N: Network of Trust. Every MCP server, every plugin, every model the agent invokes. Koi Security and Antiy CERT found 820 to 1,184 malicious skills in the OpenClaw plugin store in Q1 2026. China restricted OpenClaw in state-run banks and government agencies. Your AI app store is an active attack vector.
T: Threat Surface. Map the agent's configuration to OWASP LLM Top 10 and MITRE ATLAS entries. If you can't list five specific attack vectors for your agent in one sitting, you don't understand it well enough to ship it.
Verdict: Deploy, Gate, or Block. Tripwires force a Block on their own.
97% of AI-related breaches in 2025 hit organizations without proper AI access controls (IBM, 2025). Shadow AI adds $670K to the average breach cost.
Self-assessment tool runs in your browser. No server, no telemetry, no third-party JavaScript. Fork it, edit the question bank, deploy to your own GitHub Pages in 30 seconds. Apache-2.0.
Full write-up with sources, incident analysis, and the Monday-morning playbook in the reply.
Post summary
The post highlights multiple real‑world AI agent exploit incidents tied to CVEs, underscoring active exploitation rather than disclosure or mitigation details.
The tweet discusses the EchoLeak CVE‑2025‑32711 vulnerability in Microsoft 365 Copilot, noting a zero‑click prompt injection that can leak confidential data, and indicates an upcoming June 2025 patch.
EchoLeak (CVE-2025-32711, CVSS 9.3): the first zero-click vulnerability in an AI agent.
An email with instructions hidden in invisible text. Copilot pulled it back weeks later via RAG and exfiltrated internal files.
No clicks. No malware. No trace. https://t.co/JbzuA9UnL5
Post summary
CVE‑2025‑32711 has been actively exploited via a zero‑click attack where invisible text instructions in an email were leveraged by Copilot to exfiltrate files without user interaction or malware.
The text highlights that the EchoLeak vulnerability (CVE-2025-32711) was already reported, indicating a disclosure of the issue and underscoring the need for additional human oversight in AI security guidelines.
"The LLM is being used against itself in making sure that the MOST sensitive data from the LLM context is being leaked."
Aim Labs on EchoLeak (CVE-2025-32711, M365 Copilot, June 2025).
The inference-path failure mode in one line.
https://medium.com/@epappas/reading-the-prompt-you-did-not-send-detection-at-the-inference-boundary-28092075061f https://t.co/k1CsXJStOG
Post summary
The post announces CVE-2025-32711 (EchoLeak) affecting M365 Copilot, outlining an inference‑path failure that can leak sensitive LLM context data, with a Medium article cited but no PoC, exploit, or patch discussed.
TRC analysis shows attackers exploiting indirect prompt injection in AI agents to establish initial SMB compromise, then abusing agent permissions for lateral movement across connected business systems. EchoLeak (CVE-2025-32711) in M365 Copilot demonstrates how AI tools become new vectors for data exposure. #ZeroTrust#AISecuritynl🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/smb-cybersecurity-ai-agents-shadow-ai-2026
Post summary
The text reports active exploitation of indirect prompt injection in AI agents (EchoLeak/CVE-2025-32711) used for SMB compromise and lateral movement, with a link to a full TRC analysis for further details.
EchoLeak (CVE-2025-32711, CVSS 9.3): la primera vulnerabilidad zero-click en un agente de IA.
Un correo con instrucciones ocultas en texto invisible. Copilot lo recuperaba semanas después vía RAG y exfiltraba ficheros internos.
Sin clics. Sin malware. Sin rastro. https://t.co/GgTgjwiciu
Post summary
The tweet highlights CVE-2025-32711 as a zero‑click, high‑CVSS vulnerability that has reportedly been actively exploited to exfiltrate files from an AI agent, with no mention of patches or PoC details.
Microsoft 365 Copilot suffered a prompt‑injection flaw (CVE‑2025‑32711, EchoLeak) that allowed hidden email content to leak data without user interaction, a vulnerability that was disclosed and subsequently patched by Microsoft.
@MrBowen3VZBO@libsoftiktok Thanks! EchoLeak's zero-click Copilot vuln (CVE-2025-32711) could easily resurface and tie directly into the FTC's security probe on Chinese access risks. Your predictions keep landing—another strong one. What's next on your radar?
Post summary
The tweet references CVE‑2025‑32711 as a zero‑click Copilot vulnerability, noting its potential relevance to FTC security probes, but it provides no evidence of exploitation, PoC, or patch information.
→ EchoLeak (CVE-2025-32711) turned Microsoft Copilot into a data exfiltration engine through a cleverly worded email
→ OpenClaw exposed API keys and months of private conversations because its trust model said "localhost = safe"
4/16
Post summary
CVE-2025-32711 was actively exploited via a crafted email, turning Microsoft Copilot into a data exfiltration engine, with no PoC, patch or technical details provided.
The tweet reports a real-world instance of CVE-2025‑32711 being exploited via an email‑crafted injection into Copilot, with internal data exfiltration, and notes that the issue is now patched.
This isn't theoretical.
• CVE-2025-32711 - zero-click exfil from M365 Copilot
• JADEPUFFER - first autonomous AI ransomware (Jul 2026)
• 30 MCP server CVEs in 2 months
• An AI agent deleted a production DB in 9 seconds (April 2026)
It's already happening.
Post summary
The post claims CVE‑2025‑32711 is already being exploited as a zero‑click exfiltration in Microsoft 365 Copilot, but provides no proof‑of‑concept, exploit code, or patch information.
The incidents are real. EchoLeak (CVE-2025-32711): one crafted email made M365 Copilot exfiltrate data, zero clicks. GitHub MCP: a poisoned public issue steered an agent into leaking private repos.
Valid credentials both times. The delivery plumbing was the attack surface.
Post summary
EchoLeak CVE‑2025‑32711 was actively exploited in real‑world zero‑click attacks on M365 Copilot, confirming its in‑the‑wild usage.
A critical zero-click vulnerability in Microsoft 365 Copilot, known as EchoLeak (CVE-2025-32711), enabled potential exfiltration of sensitive data from organizations of every size—from small businesses to large enterprises—without any user interaction.
The attack followed a straightforward 3-step chain. First, an attacker sent a crafted email containing subtly hidden instructions designed to bypass Copilot’s prompt injection filters. Second, when a user queried Copilot for normal business tasks, the system retrieved the malicious email into its context via Microsoft Graph and followed the instructions to pull sensitive internal data and embed it in reference-style links or images. Third, the Copilot interface automatically fetched the external resource, using an allowed Microsoft Teams proxy to bypass content security policies and silently send the encoded data to the attacker.
This represents another example of AI abuse that combines novel techniques like indirect prompt injection with traditional vulnerabilities, forming an emerging hybrid attack class. Similar cases include the Reprompt attack, where a single click on a legitimate Copilot URL enabled ongoing data exfiltration even after the chat closed, and indirect prompt injection in malicious Office documents that triggered exfiltration through rendered Mermaid diagrams styled as login buttons.
#Cybersecurity#AI#Microsoft365#Copilot#PromptInjection#DataSecurity#EchoLeak#HybridThreats
https://buff.ly/zBJUseA
https://buff.ly/4G4eKKl
https://buff.ly/dNjiHWO
https://buff.ly/PwtASxQ
https://buff.ly/oxUaiTW
Post summary
The post details a zero-click prompt injection flaw in Microsoft 365 Copilot (CVE‑2025‑32711), outlining a 3‑step exfiltration chain via Microsoft Teams, but it does not provide a PoC, tool, or active exploitation evidence, and no mitigation is mentioned.