Untrusted content in an email can prompt an enterprise AI system to share data outside its intended scope. EchoLeak showed how that can happen. Microsoft assigned CVE-2025-32711 to EchoLeak, a zero-click attack triggered by a crafted email. Microsoft 365 Copilot pulled data from OneDrive, SharePoint, and Teams and sent it out through a trusted Microsoft ... Read more » The post Prompt injection examples and what they teach us appeared first on WitnessAI .