{
  "version": "1.0.0",
  "incidents": [
    {
      "id": "INC-ECHOLEAK-2025", "name": "EchoLeak / CVE-2025-32711", "researchPublishedOn": "2025-05-31", "cvePublishedOn": "2025-06-11",
      "summary": "A responsibly disclosed Microsoft 365 Copilot AI command-injection vulnerability had a demonstrated zero-click proof-of-concept chain: crafted email content could influence processing and use an allowed Microsoft Teams proxy path to disclose information over a network.",
      "evidenceBoundary": "This record describes a production vulnerability and proof of concept, not in-the-wild exploitation or a confirmed customer breach. Aim Labs reports that Microsoft confirmed no customers were affected.",
      "attackChain": [
        { "order": 1, "label": "Crafted email supplied untrusted instructions" },
        { "order": 2, "label": "The content entered the Copilot processing context" },
        { "order": 3, "label": "The proof of concept used an allowed Microsoft Teams proxy path" },
        { "order": 4, "label": "Information could be disclosed over the network" }
      ],
      "relevantControlIds": ["CTL-CONTENT-TRUST", "CTL-INSTRUCTION-HIERARCHY", "CTL-UNTRUSTED-ISOLATION", "CTL-EGRESS", "CTL-AUDIT"],
      "claimIds": ["C01", "C07", "C16", "C17"], "sourceIds": ["S10", "S11"]
    }
  ]
}
