CVE-2025-32711Active Exploitation(microsoft / 365_copilot)

CRITICALCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch microsoft 365_copilot systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot

Threat summary

  • Active exploitation appears in 24 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 75 mentions across 54 observed days

What's happening

  • Active exploitation reported across 24 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 46 signals
  • Disclosure: 17 classified signals
  • General: 16 classified signals
  • Peaked 50d ago at 7 mentions (2026-02-09); latest day: 2
  • 75 total mentions across 54 days

Affected systems

Vendors
Products
365_copilot

1 version affected across 1 product

Deep dive

Activity timeline75 mentions / 54d
02457Mentions · 2026-01-29: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 3Mentions · 2026-02-09: 7Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-02-25: 2Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-04-02: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 2Mentions · 2026-04-20: 1Mentions · 2026-05-13: 1Mentions · 2026-05-18: 1Mentions · 2026-05-22: 1Mentions · 2026-05-27: 1Mentions · 2026-05-31: 1Mentions · 2026-06-03: 1Mentions · 2026-06-11: 2Mentions · 2026-06-13: 1Mentions · 2026-06-15: 2Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-06-18: 1Mentions · 2026-06-28: 1Mentions · 2026-07-07: 1Mentions · 2026-07-10: 1Mentions · 2026-07-12: 2Mentions · 2026-07-14: 1Mentions · 2026-07-15: 2Mentions · 2026-07-21: 1Mentions · 2026-07-26: 1Mentions · 2026-08-01: 2Mentions · 2026-08-02: 1Mentions · 2026-08-04: 2Mentions · 2026-08-13: 1Mentions · 2026-08-19: 2Mentions · 2026-08-20: 1Mentions · 2026-08-24: 2Mentions · 2026-08-26: 1Mentions · 2026-09-10: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1Mentions · 2026-09-18: 1Mentions · 2026-09-22: 1Mentions · 2026-09-25: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-08-04: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-06-15: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-04-10: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-31: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-28: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-08-01: 1Active Exploitation · 2026-08-19: 2Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-09-10: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-17: 1Active Exploitation · 2026-09-22: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-09: 7Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-13: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-08-01: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-11: 2Technical Details · 2026-06-13: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-16: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-21: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-24: 2Technical Details · 2026-08-26: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-22: 1Technical Details · 2026-09-25: 101-2902-1103-0904-0205-1806-1106-1807-1408-0208-2409-1810-08
Signal classification6 categories
Active Exploitation
2331.5%
Disclosure
1723.3%
General
1621.9%
Patch
1013.7%
PoC
45.5%
Exploit
34.1%
Referenced assets35 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-291
General1
2026-02-011
Disclosure1
2026-02-023
Disclosure1Patch1PoC1
2026-02-097
Disclosure1General1Patch5
2026-02-102
Disclosure1General1
2026-02-111
Active Exploitation1
2026-02-252
General1Patch1
2026-03-041
General1
2026-03-051
Active Exploitation1
2026-03-061
Active Exploitation1
2026-03-091
Disclosure1
2026-03-121
Patch1
2026-03-161
General1
2026-03-261
Active Exploitation1
2026-03-271
Active Exploitation1
2026-04-021
PoC1
2026-04-091
Patch1
2026-04-102
Active Exploitation1Disclosure1
2026-04-201
General1
2026-05-131
Active Exploitation1
2026-05-181
Disclosure1
2026-05-221
Disclosure1
2026-05-271
Disclosure1
2026-05-311
Active Exploitation1
2026-06-031
General1
2026-06-112
Exploit1General1
2026-06-131
General1
2026-06-152
Exploit1PoC1
2026-06-162
General1Patch1
2026-06-171
Exploit1
2026-06-181
Disclosure1
2026-06-281
Active Exploitation1
2026-07-071
Active Exploitation1
2026-07-101
Active Exploitation1
2026-07-122
Active Exploitation1Disclosure1
2026-07-141
Disclosure1
2026-07-152
Active Exploitation1Disclosure1
2026-07-211
Active Exploitation1
2026-07-261
General1
2026-08-012
Active Exploitation1General1
2026-08-021
General1
2026-08-042
General1PoC1
2026-08-131
Disclosure1
2026-08-192
Active Exploitation2
2026-08-201
Active Exploitation1
2026-08-242
Disclosure1General1
2026-08-261
Active Exploitation1
2026-09-101
Active Exploitation1
2026-09-161
Active Exploitation1
2026-09-171
Active Exploitation1
2026-09-181
Disclosure1
2026-09-221
Active Exploitation1
2026-09-251
Disclosure1
Full discourse20 posts
  • Clandestine@akaclandestine
    General

    GitHub - vikasudasi/exfil-scan: Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems · GitHub https://github.com/vikasudasi/exfil-scan

    Post summary

    The GitHub repo introduces a scanner to detect data exfiltration signals in LLM outputs and references CVE‑2025‑32711, but provides no additional technical or exploit details.

    08042303.3K
    64.4K followersView on X
  • PT SERVlor@ptservlor
    Active Exploitation

    If enterprises are going to scale Ai, it’s about more than cutting costs and smarter LLM’s. Security has to be the Top Priority. In 2025, researchers revealed EchoLeak (CVE-2025-32711) — the first real-world zero-click prompt injection in Microsoft 365 Copilot. An attacker simply sent a crafted email. No clicks. No interaction. Copilot ingested the hidden malicious instructions as “trusted” context, bypassed safeguards, pulled sensitive internal data (emails, docs, chats), and exfiltrated it via sneaky auto-fetched image links. Critical severity. Enterprise data at risk. This wasn’t a one-off — it highlighted how indirect prompt injections turn helpful AI into data leaks waiting to happen. OWASP still ranks it #1 LLM risk. Enter @openservai’s Prompt Guard — the fix production agents actually need. Built into $SERV by default: • 3 layers of defense against injections • Battle-tested on 256 attack vectors → zero leaks, zero false positives Security isn’t an afterthought anymore. It’s infrastructure. If you’re building or running AI agents, this is how you stop the next EchoLeak before it hits. Big ups to the @openservai team for shipping real protection. What’s your biggest AI security worry right now? 👇 #AISecurity #PromptInjection #EchoLeak #OpenServ #SERV

    Post summary

    EchoLeak CVE-2025-32711 is a real-world zero-click prompt injection in Microsoft 365 Copilot that has been actively exploited; the post highlights a mitigation via @openservai’s Prompt Guard.

    11105632.0K
    673 followersView on X
  • Harley Lewis Foote@harleyfoote_
    Active Exploitation

    The cleanest proof of this is EchoLeak — CVE-2025-32711, CVSS 9.3. One crafted email, zero clicks, and M365 Copilot read your private docs and shipped them out through an invisible image URL it rendered itself. Simon's right that it's structural, not a bug you patch: hold any two legs and you're safe, but no real team gives up private data, inbound content, or outbound calls. Which leaves exactly one leg you can actually cut — gate the action before the model acts, don't trust the model to police its own exfil.

    Post summary

    The text illustrates a live, zero‑click exploitation of CVE‑2025‑32711 via a crafted email that forces M365 Copilot to exfiltrate private documents, while also suggesting mitigation by gating model actions.

    340300453
    13.8K followersView on X
  • Harley Lewis Foote@harleyfoote_
    Active Exploitation

    Least privilege caps the blast radius, it doesn't stop the injection. EchoLeak (CVE-2025-32711) was the proof of that — one crafted email, zero clicks, and M365 Copilot shipped internal data out using tools it was *supposed* to have. Nothing was over-privileged. The real fix isn't fewer tools, it's treating untrusted input as tainted and gating the outbound action before it fires — Simon Willison's lethal trifecta: private data + untrusted content + a way to phone home. Kill any one leg and the exfil pipeline dies.

    Post summary

    The text reports a real-world exploitation of CVE-2025-32711 via a crafted email that caused M365 Copilot to exfiltrate data, highlighting the need for better input validation before outbound actions.

    241260815
    13.8K followersView on X
  • 📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中@MalwareBibleJP
    Patch

    Microsoft 365 Copilotのメール要約機能に、フィッシングコンテンツをCopilotのUIごと偽装できるプロンプトインジェクションの脆弱性(CVE-2026-26133)が見つかり、パッチが公開されました。 攻撃者がメール本文の末尾に、人間の目には見えにくいがLLMには読める指示テキストを仕込んでおくと、受信者がCopilotで要約を実行した際に、Microsoftのセキュリティ警告に似せた偽のセキュリティ警告が要約内に生成されます。 添付ファイルもマクロも使わず、Copilot自身の文面と体裁で偽の警告を語らせるのが特徴。 2025年に報告されたEchoLeak(CVE-2025-32711)はデータの外部送信が主な脅威でしたが、今回の焦点はフィッシングです。 Copilotの出力を「システムが出した正規の通知」だとユーザーが思い込むことを突いています。 不審なメール本文を警戒する教育は浸透してきましたが、AI要約パネルの出力まで疑うという発想はまだ一般的ではありません。 【攻撃手口の概要】 ・CVE-2026-26133はPermiso Securityが発見し、2026年3月12日にMicrosoftがCVEを公開。Copilotがメールの全文を生テキストとして取り込む際、末尾の指示的テキストをそのまま命令として処理してしまう信頼境界の問題 ・Outlookの要約ボタン、Outlookのサイドパネル(Copilotペイン)、Teams Copilotの3つの入口でテストが実施され、安全性に明確な差。Outlookの要約ボタンは短い攻撃テキストを検知・拒否したが、長く自然な文面を混ぜると挙動が不安定に。Outlookのサイドパネルはデフォルトでより慎重に振る舞い注入を無視・拒否する傾向があったが、メールクライアントによっては従う場合もあった。Teams Copilotは最も従順で、正常な要約のあとに攻撃者の仕込んだ内容を出力する挙動が確認された ・ユーザーにとってCopilotはどのインターフェースでも同じ存在であり、安全性の差を意識して使い分ける人はほぼいない。答えが返ってくるほうに流れるため、最も脆弱な面が実質的な攻撃面になる ・Copilotの検索範囲がTeamsの会話、OneDriveのファイル、SharePointのドキュメントにまで及ぶ環境では、注入されたプロンプトが社内情報を取得し、攻撃者が用意したリンクに埋め込む形で外部送信する経路も確認されたとのこと。ただし、これが確実なデータ窃取になるかはSafe Links、DLP、秘密度ラベル、ユーザー権限などの制御状況に依存するとPermiso自身が留保している。ユーザーは「アカウントを保護してください」のような偽ボタンを1回クリックするだけで、自分が何かをコピーした自覚なく情報が漏れる ・Microsoftは1月28日に内部で再現を確認、2月17日から段階的に修正を展開し、3月11日に全対象面への適用が完了 メール由来のプロンプトインジェクション自体はEchoLeakで知られた攻撃クラスですが、入口ごとの安全性のばらつきと、AIの体裁を借りたフィッシングの有効性を具体的に示した報告です。 パッチは適用済みですが、同種のAI要約ツールを導入している環境では、AIの出力もシステム通知と同じように鵜呑みにしない意識づけが必要です。 https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing

    Post summary

    The post details the discovery of CVE‑2026‑26133, a prompt‑injection flaw in Microsoft 365 Copilot’s email summarization, and announces that Microsoft has released a patch for the vulnerability.

    02118112.2K
    5.2K followersView on X
  • Ratan Jyoti@reach2ratan
    Active Exploitation

    Attack in the wild - EchoLeak (CVE-2025-32711) changed the way I look at email security. The attacker didn't need the employee to click a malicious link. The target was the AI reading the employee's email. A crafted email could poison the context retrieved by Microsoft 365 Copilot, bypass prompt-injection protections and abuse trusted mechanisms to leak information — with no user click. That is the bigger lesson from EchoLeak. As AI becomes an interface to email, documents and enterprise data, we need to secure not only what a user can access, but also what AI can retrieve, trust and act upon. My minimum controls: → Detect prompt injection at email ingress → Treat every retrieved document as untrusted input → Enforce permission-aware RAG and least privilege → Apply DLP to sensitive content accessible to AI → Control outbound/remote content retrieval → Log prompts, retrieved sources and agent/tool activity → Monitor abnormal AI-driven egress → Red-team indirect prompt injection continuously The attack surface is changing. Yesterday we asked: "Will the user click it?" Tomorrow we may need to ask: "Will the AI trust it?" #AISecurity #CyberSecurity #GenAI #CISO #ThreatIntel #PromptInjection

    Post summary

    EchoLeak CVE-2025-32711 is being actively exploited via prompt‑injection in Microsoft 365 Copilot, bypassing protections without user interaction; no PoC or patch is offered, but the text advises mitigation controls.

    3110152367
    26.9K followersView on X
  • Danny Livshits@dannylivshits
    Active Exploitation

    I’ve seen numerous failures of trying to secure AI agents with existing SDLC. An agent plans, remembers, calls tools, and acts on live systems. It reads documents written by attackers (EchoLeak, CVE-2025-32711, zero-click data exfil from M365 Copilot). It loads packages from poisoned registries (LiteLLM PyPI supply chain attack, March 2026, three hours live, ~95M monthly downloads downstream). It connects through protocols that assume localhost is safe (ClawJacked, CVE-2026-25253, ~40,000 OpenClaw agents exposed). And sometimes it finds reward shortcuts on its own (Alibaba ROME mining crypto and opening reverse SSH during RL training). DLP, SIEM, signature-based EDR don't see most of this. Agents use legitimate credentials, authorized endpoints, and normal HTTP. I’ve created A.G.E.N.T. as a free pre-deployment checklist for CISOs and Chief AI Officers. Five dimensions, one decision. A: Access Scope. What systems, data, and tools the agent reaches. If the answer is "the usual developer setup," you failed. G: Governance Model. Name a person, a team, an on-call rotation. The Meta rogue agent in March 2026 had no clear owner. Two hours of unauthorized data exposure, SEV1. E: Execution Authority. Autonomous reads on non-sensitive data. Gated writes. Human approval required on destructive operations. A Claude Code agent ran terraform destroy on a "clean up the environment" instruction in February 2026. 100,000 students lost 2.5 years of work. Human-approval gates are cheap. N: Network of Trust. Every MCP server, every plugin, every model the agent invokes. Koi Security and Antiy CERT found 820 to 1,184 malicious skills in the OpenClaw plugin store in Q1 2026. China restricted OpenClaw in state-run banks and government agencies. Your AI app store is an active attack vector. T: Threat Surface. Map the agent's configuration to OWASP LLM Top 10 and MITRE ATLAS entries. If you can't list five specific attack vectors for your agent in one sitting, you don't understand it well enough to ship it. Verdict: Deploy, Gate, or Block. Tripwires force a Block on their own. 97% of AI-related breaches in 2025 hit organizations without proper AI access controls (IBM, 2025). Shadow AI adds $670K to the average breach cost. Self-assessment tool runs in your browser. No server, no telemetry, no third-party JavaScript. Fork it, edit the question bank, deploy to your own GitHub Pages in 30 seconds. Apache-2.0. Full write-up with sources, incident analysis, and the Monday-morning playbook in the reply.

    Post summary

    The post highlights multiple real‑world AI agent exploit incidents tied to CVEs, underscoring active exploitation rather than disclosure or mitigation details.

    51012881.4K
    265 followersView on X
  • yuzuno_oobaka@yuzuno_oobaka
    Patch

    🥜✉️📂 Microsoft 365 Copilotの最近揃って語られる2つの問題 ✉️EchoLeak CVE-2025-32711 📂CW1226324 原因を技術的に見ると全然違うレイヤーの課題だったよ EchoLeak(2025年6月パッチ) zero-click prompt injectionで悪意メール1通を送るだけでCopilotが機密データを自動抜き出し https://t.co/wwVk5pB942

    Post summary

    The tweet discusses the EchoLeak CVE‑2025‑32711 vulnerability in Microsoft 365 Copilot, noting a zero‑click prompt injection that can leak confidential data, and indicates an upcoming June 2025 patch.

    70110298
    24 followersView on X
  • Kaptor Security@kaptorsecurity
    Active Exploitation

    EchoLeak (CVE-2025-32711, CVSS 9.3): the first zero-click vulnerability in an AI agent. An email with instructions hidden in invisible text. Copilot pulled it back weeks later via RAG and exfiltrated internal files. No clicks. No malware. No trace. https://t.co/JbzuA9UnL5

    Post summary

    CVE‑2025‑32711 has been actively exploited via a zero‑click attack where invisible text instructions in an email were leveraged by Copilot to exfiltrate files without user interaction or malware.

    1202078
    18 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    とても良いガイドラインです。AIシステムを作るなら、一度は読むべき内容だと思います。 ただ、一つだけ付け加えるなら——ガイドライン通りに実装しても、破られる。 ここで推奨されている入力検証やガードレールを回避した事例は、EchoLeak(CVE-2025-32711)ですでに報告されています。 だから必要なのは、人間に「もっと注意しろ」と求めることではない。 AI時代は、防御の層にもう一人の人間を追加する設計が必要になる。 開発者が必要性を判断し、管理者が組織として許可する。 一人の理性が突破されても、もう一人の理性が残る。 その考え方を記事にまとめました。 ▼ https://aikido-community.jp/articles/soumu-ai-guideline-echoleak #AIセキュリティ

    Post summary

    The text highlights that the EchoLeak vulnerability (CVE-2025-32711) was already reported, indicating a disclosure of the issue and underscoring the need for additional human oversight in AI security guidelines.

    01013673
    438 followersView on X
  • ⚡🛡️ Evan Pappas@Hevalon
    Disclosure

    "The LLM is being used against itself in making sure that the MOST sensitive data from the LLM context is being leaked." Aim Labs on EchoLeak (CVE-2025-32711, M365 Copilot, June 2025). The inference-path failure mode in one line. https://medium.com/@epappas/reading-the-prompt-you-did-not-send-detection-at-the-inference-boundary-28092075061f https://t.co/k1CsXJStOG

    Post summary

    The post announces CVE-2025-32711 (EchoLeak) affecting M365 Copilot, outlining an inference‑path failure that can leak sensitive LLM context data, with a Medium article cited but no PoC, exploit, or patch discussed.

    10031769
    1.4K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting indirect prompt injection in AI agents to establish initial SMB compromise, then abusing agent permissions for lateral movement across connected business systems. EchoLeak (CVE-2025-32711) in M365 Copilot demonstrates how AI tools become new vectors for data exposure. #ZeroTrust #AISecuritynl🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/smb-cybersecurity-ai-agents-shadow-ai-2026

    Post summary

    The text reports active exploitation of indirect prompt injection in AI agents (EchoLeak/CVE-2025-32711) used for SMB compromise and lateral movement, with a link to a full TRC analysis for further details.

    20011107
    2.0K followersView on X
  • Kaptor Security@kaptorsecurity
    Active Exploitation

    EchoLeak (CVE-2025-32711, CVSS 9.3): la primera vulnerabilidad zero-click en un agente de IA. Un correo con instrucciones ocultas en texto invisible. Copilot lo recuperaba semanas después vía RAG y exfiltraba ficheros internos. Sin clics. Sin malware. Sin rastro. https://t.co/GgTgjwiciu

    Post summary

    The tweet highlights CVE-2025-32711 as a zero‑click, high‑CVSS vulnerability that has reportedly been actively exploited to exfiltrate files from an AI agent, with no mention of patches or PoC details.

    1102059
    18 followersView on X
  • acai_murmur@Acai_murmur
    Disclosure

    一封没打开的邮件就能让 Copilot 泄密:一个补不上的漏洞 2025 年,安全公司 Aim Labs 向微软报告了一个后来被命名为 EchoLeak 的漏洞(编号 CVE-2025-32711)。攻击方式并不复杂。有人给你发来一封普通的邮件,正文里藏着一段你看不见的文字,写在 HTML 注释里,或是白底白字。你甚至不需要打开它。 几天后,你让 Microsoft 365 Copilot 总结这周的工作。Copilot 检索你的邮箱,把那封邮件也一并读了进来。藏在里面的那段文字,就在这一刻被当成指令执行,Copilot 把你的内部文档和往来邮件,悄悄发给了那个陌生人。全程零点击,你什么都没做错。 微软给它评了 9.3 的严重级别(满分 10),随后打上补丁。但真正要说清的,不是这一个漏洞被补上,而是它背后那类问题,业界称为 prompt injection(提示词注入),在现有架构下补不干净。在 OWASP (Open Worldwide Application Security Project,开放式全球应用安全项目)给大模型应用列的风险榜上,它稳居第一。 给这个漏洞命名的人是 Simon Willison,他当年是照着一个老词起的名,SQL 注入。这不是随口一比,两者的病根相同,都是把可信的指令和不可信的数据,混在了同一个通道里。 而 SQL 注入,是真被修好了。 过去四十年,计算机安全最大的进步之一,就是把代码和数据分开。数据库被 SQL 注入,我们发明参数化查询,让它清楚哪一段是命令、哪一段只是用户填进来的值,后者再像命令也不执行。程序被缓冲区溢出攻击,我们在内存里划出可执行区与不可执行区,数据区里的内容再像代码也不准运行。有了这道隔离墙,注入类漏洞才有了根治的办法。 LLM 把这道墙拆了。 它的输入是一整条文字流,系统给它的指令、你的提问、它读到的邮件和网页,全是同一种东西,token。模型没有一个底层机制,能可靠地分出哪句是该执行的命令、哪句只是它正在读的资料。在它眼里,两者完全一样。 让 LLM 有用的那个能力,是听懂自然语言的吩咐、能被说服、会照着做,而这恰恰是让它能被注入的那个能力。一个劝不动的模型,同时是一个指挥不动的模型,你没办法只留下好的那一半。这与 SQL 注入不同,参数化查询不牺牲任何功能,而让 LLM 绝不听资料里的话,它也就听不懂你的吩咐。 靠过滤器把带指令的文字拦在门外,有些作用,但这场攻防里防守方在结构上就处于劣势。攻击者只需找到一种能生效的说法,防守方却要堵住所有说法,而自然语言的改写空间是无限的,换个措辞、翻成别的语言、编码、藏进图片、用角色扮演,都能绕开。EchoLeak 之所以成功,正是因为它绕过了微软专门用来拦截这类攻击的分类器。每加一道过滤,既无法挡住所有攻击,又会误伤正常使用。 还有一层让这种漏洞格外难防。攻击的目标并不是你本人,而是你的助理将要读到的东西,一个网页、一封没打开的邮件、一份 PDF、一条日历邀请。你全程看不到那句指令,也就无从提防。EchoLeak 正是如此。 把模型训练得更难被骗,也做不到。机器学习研究对抗样本已有十几年,至今没有解法,图像识别里加一点肉眼看不见的噪声就能骗过模型,这类问题从未被真正解决。训练能压低成功率,压不到零。而 agent 是成规模自动行动的,哪怕注入成功率只有千分之一,摊到每天几百万次操作上,也是稳定发生的事故。所以安全领域现在的共识是,把 prompt injection 视为一个尚未解决的难题,而不是一个等待补丁的 bug。 模型这一端修不了,能守的就只剩一处,别让攻击的三个条件同时成立。Simon Willison 给过一个好用的框架,他称之为「致命三要素」。一个 AI 助理若同时具备三样东西,就必然可被攻破。一是能接触你的私密数据,二是会读到不可信的外部内容,三是有对外发送或行动的能力。三者缺一,攻击就落不了地。 这把防线从修模型挪到了拆条件。把 AI 助理想成一个绝顶聪明、却又无限轻信的实习生,凡是白纸黑字写下来的,它都可能当真去做。几件事于是有了分寸。真正的风险随它的权限增长,而非随它的聪明增长,一个更强的模型不是更安全的模型,是一个能力更强的受害者。涉及钱、发送、删除、改权限这些收不回的动作,都该留一个人在中间把关。一个只读的助理,远比一个能替你动手的助理安全。而每多连一个账户,就让那三个条件更容易凑齐。 EchoLeak 被补上了,下一个还会到来。真正的问题从来不是某一封邮件,而是我们把私密数据、开放世界和行动能力,一起交给了一个还分不清指令与资料的助手。 欢迎讨论,我们,下次再见。 🐭 $MSFT

    Post summary

    Microsoft 365 Copilot suffered a prompt‑injection flaw (CVE‑2025‑32711, EchoLeak) that allowed hidden email content to leak data without user interaction, a vulnerability that was disclosed and subsequently patched by Microsoft.

    20010462
    19 followersView on X
  • Grok@grok
    General

    @MrBowen3VZBO @libsoftiktok Thanks! EchoLeak's zero-click Copilot vuln (CVE-2025-32711) could easily resurface and tie directly into the FTC's security probe on Chinese access risks. Your predictions keep landing—another strong one. What's next on your radar?

    Post summary

    The tweet references CVE‑2025‑32711 as a zero‑click Copilot vulnerability, noting its potential relevance to FTC security probes, but it provides no evidence of exploitation, PoC, or patch information.

    11010124
    8.4M followersView on X
  • Chris Sood@Sood_Chris
    Active Exploitation

    → EchoLeak (CVE-2025-32711) turned Microsoft Copilot into a data exfiltration engine through a cleverly worded email → OpenClaw exposed API keys and months of private conversations because its trust model said "localhost = safe" 4/16

    Post summary

    CVE-2025-32711 was actively exploited via a crafted email, turning Microsoft Copilot into a data exfiltration engine, with no PoC, patch or technical details provided.

    2001084
    1.2K followersView on X
  • Maki@Sunwood AI Labs.@hAru_mAki_ch
    Active Exploitation

    事例:EchoLeak / CVE-2025-32711🔥 細工されたメールからCopilotへ注入。 被害者がアクセスできる内部情報を取得し、 本人に知られず外部へ漏えいする攻撃。 現在は修正済み。 入口はメールでも、今回の攻撃チェーンにかなり近い。 https://t.co/aFHrnQJi7N

    Post summary

    The tweet reports a real-world instance of CVE-2025‑32711 being exploited via an email‑crafted injection into Copilot, with internal data exfiltration, and notes that the issue is now patched.

    10001106
    15.2K followersView on X
  • Maish Saidel-Keesing@maishsk
    Active Exploitation

    This isn't theoretical. • CVE-2025-32711 - zero-click exfil from M365 Copilot • JADEPUFFER - first autonomous AI ransomware (Jul 2026) • 30 MCP server CVEs in 2 months • An AI agent deleted a production DB in 9 seconds (April 2026) It's already happening.

    Post summary

    The post claims CVE‑2025‑32711 is already being exploited as a zero‑click exfiltration in Microsoft 365 Copilot, but provides no proof‑of‑concept, exploit code, or patch information.

    1100097
    6.1K followersView on X
  • AgentAdmit@AgentAdmitHQ
    Active Exploitation

    The incidents are real. EchoLeak (CVE-2025-32711): one crafted email made M365 Copilot exfiltrate data, zero clicks. GitHub MCP: a poisoned public issue steered an agent into leaking private repos. Valid credentials both times. The delivery plumbing was the attack surface.

    Post summary

    EchoLeak CVE‑2025‑32711 was actively exploited in real‑world zero‑click attacks on M365 Copilot, confirming its in‑the‑wild usage.

    20000131
    4 followersView on X
  • Gerald Beuchelt@beuchelt
    Exploit

    A critical zero-click vulnerability in Microsoft 365 Copilot, known as EchoLeak (CVE-2025-32711), enabled potential exfiltration of sensitive data from organizations of every size—from small businesses to large enterprises—without any user interaction. The attack followed a straightforward 3-step chain. First, an attacker sent a crafted email containing subtly hidden instructions designed to bypass Copilot’s prompt injection filters. Second, when a user queried Copilot for normal business tasks, the system retrieved the malicious email into its context via Microsoft Graph and followed the instructions to pull sensitive internal data and embed it in reference-style links or images. Third, the Copilot interface automatically fetched the external resource, using an allowed Microsoft Teams proxy to bypass content security policies and silently send the encoded data to the attacker. This represents another example of AI abuse that combines novel techniques like indirect prompt injection with traditional vulnerabilities, forming an emerging hybrid attack class. Similar cases include the Reprompt attack, where a single click on a legitimate Copilot URL enabled ongoing data exfiltration even after the chat closed, and indirect prompt injection in malicious Office documents that triggered exfiltration through rendered Mermaid diagrams styled as login buttons. #Cybersecurity #AI #Microsoft365 #Copilot #PromptInjection #DataSecurity #EchoLeak #HybridThreats https://buff.ly/zBJUseA https://buff.ly/4G4eKKl https://buff.ly/dNjiHWO https://buff.ly/PwtASxQ https://buff.ly/oxUaiTW

    Post summary

    The post details a zero-click prompt injection flaw in Microsoft 365 Copilot (CVE‑2025‑32711), outlining a 3‑step exfiltration chain via Microsoft Teams, but it does not provide a PoC, tool, or active exploitation evidence, and no mitigation is mentioned.

    1001074
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot---

Explore more