Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Will there be a ‘September surge’ in hiring this year? Experts weigh in

Perplexity AI tables $34.5 billion cash bid for Google’s Chrome amid Antitrust pressure

Moveworks Recognized as a Challenger in the 2025 Gartner® Magic Quadrant™ for Artificial Intelligence Applications in IT Service Management

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Industry Applications

Zero-Click Microsoft Copilot Vuln Underscores Emerging AI Security Risks

By Advanced AI EditorJune 19, 2025No Comments6 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


(Source: inray27/Shutterstock)

A critical security vulnerability in Microsoft Copilot that could have allowed attackers to easily access private data serves as a potent demonstration of the real security risks of generative AI. The good news is that while CEOs are gung-ho over AI, security professionals are pressing to make bigger investments in security and privacy, studies show.

The Microsoft Copilot vulnerability, dubbed EchoLeak, was listed as CVE-2025-32711 in the NIST’s National Vulnerability Database, which gave the flaw a severity score of 9.3. According to Aim Labs, which discovered EchoLeak and shared its research with the world last week, the “zero-click” flaw could “allow attackers to automatically exfiltrate sensitive and proprietary information from M365 Copilot context, without the user’s awareness, or relying on any specific victim behavior.” Microsoft patched the flaw the following day.

EchoLeak serves as a wakeup call to the industry that new AI methods also bring with them new attack surfaces and therefore new security vulnerabilities. While nobody appears to have been harmed with EchoLeak, per Microsoft, the attack is based on a “general design flaws that exist in other RAG applications and AI agents,” Aim Labs states.

Those concerns are reflected in a slew of studies released over the past week. For instance, a survey of more than 2,300 senior GenAI decision makers released today by NTT DATA found that “while CEOs and business leaders are committed to GenAI adoption, CISOs and operational leaders lack the necessary guidance, clarity and resources to fully address security risks and infrastructure challenges associated with deployment.”

(Source: Irfan Hik/Shutterstock)

NTT Data found that 99% of C-Suite executives “are planning further GenAI investments over the next two years, with 67% of CEOs planning significant commitments.” Some of those funds will go to cybersecurity, which was cited as a top investment priority for 95% of CIOs and CTOs, the study said.

“Yet, even with this optimism, there is a notable disconnect between strategic ambitions and operational execution with nearly half of CISOs (45%) expressing negative sentiments toward GenAI adoption,” NTT DATA said. “More than half (54%) of CISOs say internal guidelines or policies on GenAI responsibility are unclear, yet only 20% of CEOs share the same concern–revealing a stark gap in executive alignment.”

The study found other disconnects between the GenAI hopes and dreams of the higher ups and the hard realities of those closer to the ground. Nearly two-thirds of CISOs say their teams “lack the necessary skills to work with the technology.” What’s more, only 38% of CISOs say their GenAI and cybersecurity strategies are aligned, compared to 51% of CEOs, NTT DATA found.

“As organizations accelerate GenAI adoption, cybersecurity must be embedded from the outset to reinforce resilience. While CEOs champion innovation, ensuring seamless collaboration between cybersecurity and business strategy is critical to mitigating emerging risks,” stated Sheetal Mehta, senior vice president and global head of cybersecurity at NTT DATA. “A secure and scalable approach to GenAI requires proactive alignment, modern infrastructure, and trusted co-innovation to protect enterprises from emerging threats while unlocking AI’s full potential.”

Another study released today, this one from Nutanix, found that leaders at public sector organizations want more investment in security as they adopt AI.

The company’s latest Public Sector Enterprise Cloud Index (ECI) study found that 94% of public sector organizations are already adopting AI, such as for content generation or chatbots. As they modernize their IT systems for AI, leaders want their organizations to increase investments in security and privacy too.

(Source: one photo/Shutterstock)

The ECI indicates that “a significant amount of work needs to be done to improve the foundational levels of data security/governance required to support GenAI solution implementation and success,” Nutanix said. The good news is that 96% of survey respondents agreed that security and privacy are becoming higher priorities with GenAI.

“Generative AI is no longer a future concept, it’s already transforming how we work,” said Greg O’Connell, vice president of public sector federal sales at Nutanix. “As public sector leaders look to see outcomes, now is the time to invest in AI-ready infrastructure, data security, privacy, and training to ensure long-term success.”

Meanwhile, the folks over at Cybernews–which is an Eastern European security news site with its own team of white hat researchers–analyzed the public-facing websites of companies across the Fortune 500 and discovered that all of them are using AI in one form or another.

The Cybernews research project, which utilized Google’s Gemini 2.5 Pro Deep Research model for text analysis, made some interesting findings. For instance, it found that 33% of the Fortune 500 say they’re using AI and big data in a broad manner for analysis, pattern recognition, and optimization, while about 22% are using AI for specific business functions like inventory optimization, predictive maintenance, and customer service.

The research project found 14% have developed proprietary LLMs, such as Walmart’s Wallaby or Saudi Aramco’s Metabrain, while about 5% are using LLM services from third-party providers like OpenAI, DeepSeek AI, Anthropic, Google, and others.

While AI use is now ubiquitous, the corporations are not doing enough to mitigate risks of AI, the company said.

“While big companies are quick to jump to the AI bandwagon, the risk management part is lagging behind,” Aras Nazarovas, a senior security researcher at Cybernews, said in the company’s June 12 report. “Companies are left exposed to the new risks associated with AI.”

These risks range from data security and data leakage, which Cybernews said is the most commonly mentioned security concern, to other concerns like prompt injection and model poisoning. New vulnerabilities created in energy control systems algorithmic bias, IP theft, insecure output, and an overall lack of transparency round out the list.

“As companies start to grapple with new challenges and risks, it’s likely to have significant implications for consumers, industries, and the broader economy in the coming years,” Nazarovas said.

This article first appeared on BigDATAwire.

Related

About the author: Alex Woodie

Alex Woodie has written about IT as a technology journalist for more than a decade. He brings extensive experience from the IBM midrange marketplace, including topics such as servers, ERP applications, programming, databases, security, high availability, storage, business intelligence, cloud, and mobile enablement. He resides in the San Diego area.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleC3 AI Lists Solutions in AWS Marketplace in the AWS Secret Region
Next Article Grok and Mixtral AI Models Hijacked by WormGPT Clones via Prompt Jailbreaks
Advanced AI Editor
  • Website

Related Posts

Mobile and Voice Are Coming to Harvey – Artificial Lawyer

September 10, 2025

Tesla targets Bay Area airports as next step for Robotaxi rollout

September 10, 2025

Meet Blueshoe, the YC-Backed Legal Research Challenger – Artificial Lawyer

September 10, 2025
Leave A Reply

Latest Posts

Growing Support for Parthenon Marbles’ Return to Greece, More Art News

Leon Black and Leslie Wexner’s Letters to Jeffrey Epstein Released

School of Visual Arts Transfers Ownership to Nonprofit Alumni Society

Cristin Tierney Moves Gallery to Tribeca for 15th Anniversary Exhibition

Latest Posts

Will there be a ‘September surge’ in hiring this year? Experts weigh in

September 10, 2025

Perplexity AI tables $34.5 billion cash bid for Google’s Chrome amid Antitrust pressure

September 10, 2025

Moveworks Recognized as a Challenger in the 2025 Gartner® Magic Quadrant™ for Artificial Intelligence Applications in IT Service Management

September 10, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Will there be a ‘September surge’ in hiring this year? Experts weigh in
  • Perplexity AI tables $34.5 billion cash bid for Google’s Chrome amid Antitrust pressure
  • Moveworks Recognized as a Challenger in the 2025 Gartner® Magic Quadrant™ for Artificial Intelligence Applications in IT Service Management
  • Mobile and Voice Are Coming to Harvey – Artificial Lawyer
  • Growing Support for Parthenon Marbles’ Return to Greece, More Art News

Recent Comments

  1. TimsothyReaws on Foundation AI: Cisco launches AI model for integration in security applications
  2. ArlieSlomE on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  3. Juniorfar on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  4. ArlieSlomE on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  5. Edwinbub on Foundation AI: Cisco launches AI model for integration in security applications

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.