Researchers at Aim Security have just disclosed a world first: an AI security vulnerability that has been given a Common Vulnerabilities and Exposures classification. The EchoLeak zero-click vulnerability, CVE-2025-32711, is a big deal, but it’s also a warning of things to come.
“The critical vulnerability enables external attackers to remotely exfiltrate sensitive data from an organisation by only sending an email,” the researchers said.
Yes, this is a zero-click vulnerability, one that can be exploited without user interaction and, it would appear, without the user even being aware that an attack is happening. And that attack has consequences: the ability to exfiltrate sensitive information by way of Microsoft 365 Copilot AI context.
No wonder, then, that Microsoft itself has rated this as a critical vulnerability and has already fixed the issue.
EchoLeak marks arrival of AI security risks
EchoLeak is a warning of things to come, unless I am very much mistaken. Hint: I’m not.
And Ensar Seker, CISO at SOCRadar, agrees. Given that “well-guarded AI agents like Microsoft 365 Copilot can be weaponised through what Aim Labs correctly terms an LLM Scope Violation”, Seker explained, this is a new era.
What’s more, it bypasses server-side classifiers and markdown redaction rules, which “demonstrates how these vulnerabilities are baked into agent-level logic, not just surface UI flows” he added.
Tim Erlin, Security Strategist at Wallarm, provided a similarly stark warning.
“Agentic AI makes these kinds of exploit techniques more dangerous to users and more attractive to attackers,” he said.
Imagine that you can receive an email that could trigger an AI agent into buying the sender a plane ticket, without you even knowing. “We’re talking about connecting the unknown AI attack surface to any action that can be carried out over an API,” Erlin added.
EchoLeak is just the beginning
Here’s the thing, though. This might be a first, but as I’ve made quite clear already, I don’t think it will be the last such vulnerability.
Brian Fox, CTO & Co-Founder at Sonatype, agrees. “It’s not just a security bug — it’s a signal that the fundamental assumptions behind AI agent design are flawed.”
Fox called EchoLeak the first ripple and warned that “we should expect echoes of familiar vulnerability patterns to resurface, only now, in the context of autonomous systems capable of acting on data at scale and speed”.
So, what needs to be done?
“The response here shouldn’t be to stop or slow down AI, but to speed up the creation of practical controls,” Erlin concluded. “If security is often an afterthought, governance is a distant third, but we need both when it comes to AI apps and agents.”
Related articles