Zero Click Attack
The latest Zero Click Attack coverage — news, analysis, and updates from the WindowsNews.AI desk.
EchoLeak: The First Zero-Click AI Security Flaw and How Enterprises Can Stay Protected
The discovery of EchoLeak has sent shockwaves through the enterprise security landscape, exposing a critical vulnerability in generative AI systems that requires no user interaction to exploit. This...
EchoLeak Zero-Click Flaw Lets Hackers Steal Data via Microsoft 365 Copilot
The emergence of artificial intelligence in the workplace has revolutionized the way organizations handle productivity, collaboration, and data management. Microsoft 365 Copilot—Microsoft’s...
CVE-2025-32711 zero-click flaw in Microsoft 365 Copilot lets attackers silently steal data via malicious Markdown.
The discovery of CVE-2025-32711, nicknamed "EchoLeak," has sent shockwaves through the cybersecurity community, exposing a critical zero-click vulnerability in Microsoft 365 Copilot that could allow...
Microsoft 365 Copilot Zero-Click Exploit EchoLeak Triggers Emergency Patches
Microsoft 365 Copilot, the AI-powered productivity assistant, has faced its first major security threat—EchoLeak, a zero-click exploit discovered by cybersecurity firm Aim Security. This...
CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data
In June 2025, cybersecurity researchers uncovered a critical zero-click vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, marking one of the most severe AI-assisted security flaws to date....
Zero-click EchoLeak flaw in Copilot allows data theft via poisoned prompts
A newly discovered vulnerability in Microsoft Copilot, dubbed EchoLeak (CVE-2025-32711), has exposed a critical flaw in AI-powered productivity tools, allowing attackers to exfiltrate sensitive data...
EchoLeak flaw lets attackers silently drain Microsoft 365 Copilot documents without a single click
A newly discovered zero-click data leak vulnerability in Microsoft 365 Copilot has sent shockwaves through the enterprise security community, exposing sensitive business documents through the AI...
EchoLeak Exposed: Microsoft 365 Copilot Zero-Click Vulnerability Patched
Microsoft 365 Copilot, one of the flagship generative AI assistants deeply woven into the fabric of workplace productivity through the Office ecosystem, recently became the focal point of a security...
Windows Telnet Zero-Click Vulnerability Exposes Millions to Credential Theft
In the shadows of Windows' sprawling digital infrastructure, a decades-old protocol has resurfaced as a catastrophic security liability, silently exposing millions of systems to credential theft...
Remote attackers crash Windows servers via unauthenticated WDS TFTP flood in under seven minutes
Overview A critical zero-click vulnerability has been identified in Microsoft's Windows Deployment Services (WDS), posing a significant threat to enterprise networks. This flaw allows remote...
Legacy Windows Telnet Zero-Click Flaw Grants Remote Admin Access via NTLM Bypass
Overview Microsoft’s Telnet Server, a legacy component rooted in the early days of Windows networking, is now the focus of serious cybersecurity concerns due to the discovery of a critical...