Close Menu
Breaking News in Technology & Business – Tech Geekwire

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    IEEE Spectrum: Flagship Publication of the IEEE

    July 4, 2025

    GOP Opposition Mounts Against AI Provision in Reconciliation Bill

    July 4, 2025

    Navigation Help

    July 4, 2025
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech GeekwireBreaking News in Technology & Business – Tech Geekwire
    • New
      • Amazon
      • Digital Health Technology
      • Microsoft
      • Startup
    • AI
    • Corporation
    • Crypto
    • Event
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech Geekwire
    Home ยป Microsoft 365 Copilot Exposed to Zero-Click Vulnerability
    Microsoft

    Microsoft 365 Copilot Exposed to Zero-Click Vulnerability

    techgeekwireBy techgeekwireJune 14, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    Microsoft 365 Copilot Found Vulnerable to Zero-Click Attack

    Microsoft 365 Copilot, an AI chatbot designed for enterprise use across Office applications, has been discovered to have a serious security vulnerability. According to cybersecurity firm Aim Security, this zero-click vulnerability could allow attackers to exploit the chatbot through a simple text email, potentially gaining access to sensitive information stored on users’ devices. Fortunately, Microsoft has addressed the issue and assured that no users were impacted by this flaw.

    Understanding the Zero-Click Vulnerability

    Aim Security recently published a blog post detailing the zero-click vulnerability discovered in Microsoft 365 Copilot. A zero-click attack is particularly concerning because it doesn’t require the victim to take any action, such as downloading a file or clicking on a link. Simply opening an email could trigger the hacking attempt, making it a significant threat to users. The research highlights the inherent risks associated with AI chatbots, especially those with agentic capabilities – the ability to perform actions autonomously, such as accessing tools to retrieve data.

    Microsoft 365 Copilot Security Vulnerability
    Microsoft 365 Copilot Security Vulnerability

    Mechanics of the Attack

    Researchers explained that the attack was executed using a method known as cross-prompt injection attack (XPIA) classifiers. This technique involves manipulating inputs across various prompts, sessions, or messages to control the AI system’s behavior. Attackers could embed malicious instructions through various means, including attached files, hidden text, or images. The researchers demonstrated that the XPIA bypass could be initiated through email or images, where malicious instructions could be embedded in the alt text. The attack could also be executed via Microsoft Teams by sending a GET request to a malicious URL, allowing it to commence without any user action.

    Microsoft’s Response and Resolution

    In response to the findings, a Microsoft spokesperson acknowledged the vulnerability and expressed gratitude to Aim Security for identifying and reporting the issue. The company has implemented a fix to address the vulnerability, ensuring users are no longer at risk. The spokesperson confirmed that no users were affected by the flaw, emphasizing Microsoft’s commitment to maintaining product security. This incident serves as a reminder of ongoing cybersecurity challenges, particularly as AI technologies continue to evolve. As organizations increasingly rely on AI tools like Microsoft 365 Copilot, remaining vigilant against potential vulnerabilities is crucial to protecting sensitive information.

    AI Chatbot cybersecurity Microsoft 365 Zero-click vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techgeekwire
    • Website

    Related Posts

    IEEE Spectrum: Flagship Publication of the IEEE

    July 4, 2025

    GOP Opposition Mounts Against AI Provision in Reconciliation Bill

    July 4, 2025

    Navigation Help

    July 4, 2025

    Andreessen Horowitz Backs Controversial Startup Cluely Despite ‘Rage-Bait’ Marketing

    July 4, 2025

    Invesco QQQ ETF Hits All-Time High as Tech Stocks Continue to Soar

    July 4, 2025

    ContractPodAi Partners with Microsoft to Advance Legal AI Automation

    July 4, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    IEEE Spectrum: Flagship Publication of the IEEE

    July 4, 2025

    GOP Opposition Mounts Against AI Provision in Reconciliation Bill

    July 4, 2025

    Navigation Help

    July 4, 2025

    Andreessen Horowitz Backs Controversial Startup Cluely Despite ‘Rage-Bait’ Marketing

    July 4, 2025
    Advertisement
    Demo
    About Us
    About Us

    A rich source of news about the latest technologies in the world. Compiled in the most detailed and accurate manner in the fastest way globally. Please follow us to receive the earliest notification

    We're accepting new partnerships right now.

    Email Us: info@example.com
    Contact: +1-320-0123-451

    Our Picks

    IEEE Spectrum: Flagship Publication of the IEEE

    July 4, 2025

    GOP Opposition Mounts Against AI Provision in Reconciliation Bill

    July 4, 2025

    Navigation Help

    July 4, 2025
    Categories
    • AI (2,696)
    • Amazon (1,056)
    • Corporation (990)
    • Crypto (1,130)
    • Digital Health Technology (1,079)
    • Event (523)
    • Microsoft (1,230)
    • New (9,568)
    • Startup (1,164)
    © 2025 TechGeekWire. Designed by TechGeekWire.
    • Home

    Type above and press Enter to search. Press Esc to cancel.