<ul data-eligibleForWebStory="true">CVE-2025-32711, known as 'EchoLeak,' is a critical vulnerability in Microsoft's Copilot AI enabling a zero-click attack.It exploits an 'LLM scope violation' and is the first known zero-click attack on an AI agent.The discovery highlights the growing intersection between traditional software vulnerabilities and AI threats.Cyber defenders need to adjust defense strategies to tackle such novel threats proactively.The attack allows automatic exfiltration of sensitive data without user interaction in M365 Copilot.Microsoft confirmed resolution of the issue and provided mitigation measures like DLP tags.Exploitation of AI vulnerabilities emphasizes the need for proactive defenses and threat modeling.SOC Prime Platform offers products to strengthen cybersecurity resilience against AI-driven threats.