A threat analysis diagram showing how the CVE-2025-32711 EchoLeak vulnerability uses indirect prompt injection to trigger a zero-click attack in Microsoft Copilot.

EchoLeak Zero-Click Disaster: How Microsoft Copilot’s AI Flaw Exposes Your Company’s Secrets Automatically

FROM: The BC Threat Intelligence GroupTO: Enterprise CISOs, Security Architects, AI Governance CommitteesDATE: November 2, 2025SUBJECT: CVE-2025-32711 “EchoLeak” – The Zero-Click AI Vulnerability That Changes …

EchoLeak Zero-Click Disaster: How Microsoft Copilot’s AI Flaw Exposes Your Company’s Secrets Automatically Read More