PipeRoll - Agent Incident Registry

PIR-2026-0017

EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711)
Cite as: PipeRoll PIR-2026-0017, EchoLeak: zero-click prompt-injection data exfiltration in Microsoft… (2025) - https://piperoll.org/pir/2026-0017

PIR-2026-0017 - EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711)

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Independence: strong - independent security firms + arXiv + trade press corroborate the researcher account; the "no exploitation" claim is single-source (Microsoft). - confidence: high on mechanism, dates, and CVE (multiple independent sources agree); medium on the no-in-wild-exploitation claim (vendor attestation only)

Verification notes