Microsoft 365 Copilot ‘zero-click’ vulnerability enabled data exfiltration

An attacker could have sent an email causing Copilot to leak info via a markdown image.