Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Zero-Click M365 Copilot Exploit EchoLeak - Deep Dive

Donato Capitella via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore a comprehensive technical analysis of the EchoLeak vulnerability affecting Microsoft 365 Copilot in this 38-minute deep dive presentation. Examine how this zero-click exploit enables data exfiltration through a simple email sent to users of Microsoft Office 365 Copilot, requiring no user interaction beyond receiving the malicious message. Learn about the vulnerability's mechanics through detailed coverage of data exfiltration techniques using Markdown images, understand how Copilot functions as a RAG (Retrieval-Augmented Generation) system operating on the Enterprise Graph, and analyze the complete attack chain from initial email delivery to successful data extraction. Discover advanced strategies for poisoning the RAG latent space, investigate LLM scope violations that enable unauthorized access to sensitive information, and gain insights into the broader security implications for enterprise AI systems. The presentation includes practical lessons learned from this vulnerability research and provides essential knowledge for security professionals working with AI-powered enterprise tools.

Syllabus

00:00 - Introduction
02:57 - Executive Summary
04:48 - Background Context on Data Exfiltration via Markdwon Images
08:00 - Copilot as a RAG System on the Enterprise Graph
10:46 - Full Attack Chain Analysis
24:17 - Strategies to Poison the RAG Latent Space
29:43 - LLM Scope Violation
32:44 - Lessons Learnt

Taught by

Donato Capitella

Reviews

Start your review of Zero-Click M365 Copilot Exploit EchoLeak - Deep Dive

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.