Vietnam.vn - Nền tảng quảng bá Việt Nam

The first attack to occur with AI

With just a seemingly harmless email, the Microsoft Copilot AI assistant can automatically reveal confidential data without any user intervention.

ZNewsZNews12/06/2025

Hackers are attacking Microsoft 365 Copilot. Photo: Bloomberg .

A serious security flaw has been discovered in Microsoft 365 Copilot, the AI assistant built into the office suite of applications such as Word, Excel, Outlook, PowerPoint, and Teams. The discovery, made public by cybersecurity firm Aim Security, raises concerns about attacks on AI agents.

The vulnerability, dubbed EchoLeak by Aim Security, allows attackers to access critical data without any action from the user. It is the first known “zero-click” attack against an AI agent, a system that uses a large language model (LLM) to perform tasks automatically.

AI Agents in Sight

In the case of Microsoft Copilot, an attacker would simply send an email containing a hidden link to a user. Since Copilot automatically scans emails in the background, it reads and executes these commands without requiring interaction from the recipient. As a result, the AI can be manipulated to access and exfiltrate documents, spreadsheets, and internal messages and relay the data back to the hacker.

“We appreciate Aim Security for responsibly identifying and reporting this issue so it could be resolved before customers were impacted. Product updates have been deployed and no action is required from users,” a Microsoft spokesperson confirmed to Fortune.

Tac nhan AI anh 1

Aim Security warns hackers are looking to exploit Microsoft 365 Copilot. Photo: Bloomberg .

However, according to Aim Security, the problem lies deeper in the underlying design of AI agents. Adir Gruss, co-founder and CTO of Aim Security, said the EchoLeak vulnerability is a sign that current AI systems are repeating security mistakes from the past.

“We found a series of vulnerabilities that allowed an attacker to perform the equivalent of a zero-click attack on a phone, but this time against an AI system,” Gruss said. He said the team spent about three months analyzing and reverse engineering Microsoft Copilot to determine how the AI could be manipulated.

Although Microsoft responded and deployed a patch, Gruss said the five-month fix was "a long time for the severity of the problem." He explained this was partly due to the newness of the vulnerability concept and the time it took for Microsoft's engineering teams to identify and act.

History repeats itself?

According to Gruss, EchoLeak affects not only Copilot but can also be applied to similar platforms such as Agentforce (Salesforce) or Anthropic's MCP protocol.

“If I were leading a company that was deploying an AI agent, I would be terrified. This is the kind of design flaw that has caused decades of damage in the tech industry, and now it’s coming back with AI,” Gruss said.

Tac nhan AI anh 2

Microsoft has deployed measures to fix the vulnerability on Copilot. Photo: Bloomberg .

The root cause of this problem is that current AI agents do not distinguish between trustworthy and untrustworthy data. Gruss believes that the long-term solution is to completely redesign the way AI agents are built, with the ability to clearly distinguish between valid data and dangerous information.

Aim Security is currently providing temporary mitigations for some customers using AI agents. However, this is only a temporary fix and a new system redesign can ensure information security for users.

“Every Fortune 500 company I know is scared to deploy AI agents into production. They may be experimenting, but vulnerabilities like this keep them up at night and slow down innovation,” said Aim Security CTO.

Source: https://znews.vn/tac-nhan-ai-dau-tien-bi-tan-cong-post1560190.html


Comment (0)

No data
No data
Magical scene on the 'upside down bowl' tea hill in Phu Tho
3 islands in the Central region are likened to Maldives, attracting tourists in the summer
Watch the sparkling Quy Nhon coastal city of Gia Lai at night
Image of terraced fields in Phu Tho, gently sloping, bright and beautiful like mirrors before the planting season
Z121 Factory is ready for the International Fireworks Final Night
Famous travel magazine praises Son Doong cave as 'the most magnificent on the planet'
Mysterious cave attracts Western tourists, likened to 'Phong Nha cave' in Thanh Hoa
Discover the poetic beauty of Vinh Hy Bay
How is the most expensive tea in Hanoi, priced at over 10 million VND/kg, processed?
Taste of the river region

Heritage

Figure

Business

No videos available

News

Political System

Local

Product