First ever security flaw detected in an AI agent, could allow hacker to attack user via email

Security researchers have discovered the first zero-click AI vulnerability in Microsoft 365 Copilot AI agent, exposing a way for attackers to steal data via email without user interaction. The flaw is now fixed.