Microsoft EchoLeak vulnerability highlights zero-click data exfiltration risks in AI
The article discusses the EchoLeak (CVE-2025-32711) vulnerability in Microsoft 365 Copilot, which demonstrates a 'zero-click' prompt injection flaw capable of unauthorized data exfiltration. It advises product managers and engineers on evaluating LLM security practices and defending against risks highlighted in the OWASP Top 10 for LLM Applications.
Key Takeaways
- EchoLeak (CVE-2025-32711) achieved a critical CVSS score of 9.3 by enabling data theft without any user interaction.
- Prompt injection is currently the top-ranked risk on the OWASP Top 10 for LLM Applications as of the 2025 revision.
- The vulnerability bypasses traditional defenses like SOC 2 or encryption because LLMs treat instructions and data as a single tokens stream.
- Attack vectors identified include jailbreaking, sensitive context leakage, 'denial of wallet' token-cost attacks, and excessive agency findings.
Why It Matters
This incident marks a shift from theoretical AI risks to operational vulnerabilities in major B2B production environments. Because prompt injection exploits the fundamental architectural design of LLMs—specifically the lack of separation between code and data—it cannot be entirely mitigated by traditional patching. For the streaming and enterprise tech ecosystems, this necessitates a move toward 'defense-in-depth' strategies, including output monitoring and scoped data access, rather than relying on compliance checkboxes. Decision-makers should watch for the adoption of the 2026 NIST AI Risk Management Framework updates, which shift focus from model-centric safety to execution-layer agent security.
Additional Context
The EchoLeak disclosure in June 2025 by Aim Security researchers prompted Microsoft to issue a server-side patch through its June Patch Tuesday update. Per Checkmarx, the vulnerability specifically bypassed Cross-Prompt Injection Attack (XPIA) classifiers by framing malicious instructions as benign text meant for a human recipient. While Microsoft confirmed no evidence of active exploitation in the wild, the incident has catalyzed broader industry efforts to standardize AI threat modeling. In October 2025, MITRE ATLAS expanded its framework with 14 new techniques specifically targeting autonomous agents, covering risks like context poisoning and memory manipulation. Beyond Microsoft, the scale of natural language exploits is expanding rapidly across the enterprise landscape. According to CrowdStrike’s 2026 Global Threat Report, prompt injection attacks impacted more than 90 organizations throughout 2025, with approximately 82% of those intrusions involving no traditional malicious code. This trend coincides with findings from the OWASP 2026 LLM Security Report, which documented a 340% year-over-year surge in prompt injection attempts as companies pivot from simple chatbots to agentic systems with higher operational agency and tool access. Regulatory and standards bodies are now accelerating their response to these non-code-based threats. By May 2026, the NIST AI Risk Management Framework (AI RMF) introduced sector-specific 'Profiles' to help organizations operationalize defenses against indirect prompt injection. Concurrently, MITRE launched a beta version of its AI Risk Database to track incidents like the 'Morris II' worm, which demonstrated how AI agents can be manipulated to propagate malicious prompts across RAG-enabled email databases without manual intervention.
Read full article at infinum.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source