A critical AI vulnerability, ‘EchoLeak,’ was discovered in Microsoft 365 Copilot by Aim Labs researchers in January 2025. This flaw allowed attackers to exfiltrate sensitive user data through malicious emails with hidden prompt injections. Microsoft swiftly addressed the issue with a server-side fix in May 2025, confirming no evidence of real-world exploitation.