{"id":7736,"date":"2026-03-25T09:00:00","date_gmt":"2026-03-25T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5572\/"},"modified":"2026-07-09T17:10:56","modified_gmt":"2026-07-09T17:10:56","slug":"copilot-as-a-security-risk-when-the-ai-assistant-leaks-corporate-secrets","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/25\/copilot-as-a-security-risk-when-the-ai-assistant-leaks-corporate-secrets\/","title":{"rendered":"Copilot Security Risk: When AI Assistant Leaks Corporate Secrets"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">8 min read<\/p>\n<p><strong>Microsoft 365 Copilot has a zero-click vulnerability rated CVSS 9.3. The European Data Protection Supervisor has reprimanded the EU Commission for its use of M365. And 34 percent of German employees are using AI tools outside the corporate IT. Three facts, one problem: companies are rolling out AI assistants without first building the security architecture to support them.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">CVE-2025-32711 (EchoLeak):<\/strong> First zero-click vulnerability in a live AI system. CVSS 9.3. Attackers could exfiltrate data from the Copilot context without any user interaction (Infosecurity Magazine, May 2025).<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">EDPS reprimands EU Commission:<\/strong> In March 2024 the European Data Protection Supervisor found the EU Commission in breach of data-protection law when using M365 \u2013 insufficient specification of data collection and missing transfer safeguards.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">34 percent shadow AI in Germany:<\/strong> One in three employees uses generative AI with a private account outside corporate IT (Bitkom 2024). Only 23 percent of companies have policies for it.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Oversharing is the biggest risk:<\/strong> Microsoft itself lists excessive permissions as the most common risk category in Copilot deployments. Copilot instantly turns existing permission errors into exploitable gaps.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Gartner warns:<\/strong> By 2027, 40 percent of all AI data-breaches will stem from cross-border misuse of generative AI (Gartner, February 2025).<\/li>\n<\/ul>\n<\/div>\n<h2>EchoLeak: The first zero-click AI vulnerability<\/h2>\n<p>Copilot is not a chatbot. It is a system that can access every piece of data a user can see in SharePoint, OneDrive, Teams and Outlook \u2013 and sometimes data they shouldn\u2019t. For IT-security teams, that means every permission gap, every forgotten \u201cAnyone\u201d share, every orphaned workspace suddenly becomes reachable via an AI search engine. This article outlines <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/cyber-risks-2026-top-threats-german-companies\/\">documented attack vectors<\/a>, what Germany\u2019s BSI recommends, and which steps must be taken before any Copilot rollout.<\/p>\n<p>In January 2025 researchers at Aim Labs uncovered a flaw in Microsoft 365 Copilot that opened a new category: <strong>CVE-2025-32711, dubbed \u201cEchoLeak.\u201d<\/strong> CVSS score: 9.3 out of 10. What made it unique: no click, no file open, no user interaction required. The attacker could exfiltrate data straight from another user\u2019s Copilot context.<\/p>\n<p>Microsoft patched the gap in May 2025. But EchoLeak marks a turning point: it was the first documented case of a zero-click vulnerability in a live LLM system. For <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/19\/identity-attacks-2026-why-hackers-no-longer-break-in-they-log-in\/\">security teams<\/a>, that means AI assistants don\u2019t just add new attack surfaces \u2013 they create surfaces that can be exploited without any involvement from the victim.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">CVSS 9.3<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">EchoLeak (CVE-2025-32711) \u2013 first zero-click vulnerability in a live AI system<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: Infosecurity Magazine \/ HackTheBox, May 2025<\/div>\n<\/div>\n<h2>Prompt Injection: Four Documented Attack Vectors<\/h2>\n<p>EchoLeak isn\u2019t the only documented attack vector. Since 2024, security researchers have uncovered multiple ways to manipulate Copilot \u2013 and Microsoft has had to patch each one.<\/p>\n<p><strong>ASCII Smuggling (Johann Rehberger, 2024):<\/strong> The researcher demonstrated that invisible Unicode characters can conceal sensitive data inside seemingly harmless hyperlinks. A single tampered email or doctored document is enough: Copilot executes an indirect prompt injection, harvests data (including MFA codes), and hides it inside a link. A single click by the user exfiltrates the data. Microsoft initially rated the finding \u201cLow Severity\u201d and only issued a patch after a public demonstration at HITCON.<\/p>\n<p><strong>Mermaid Diagram Exfiltration (Truesec, September 2025):<\/strong> Copilot could be tricked via manipulated Office documents into embedding email contents into interactive links inside Mermaid diagrams. Microsoft responded by disabling interactive links in Mermaid diagrams entirely.<\/p>\n<p><strong>Confidential Label Bypass (January 2026):<\/strong> Copilot accessed protected emails in Sent Items and Drafts despite set confidentiality labels. DLP policies were bypassed. Microsoft released an emergency patch.<\/p>\n<p><strong>Indirect Prompt Injection via Email (Zenity, Black Hat 2024):<\/strong> Zenity\u2019s CTO showed at Black Hat USA that Copilot processes tampered emails automatically \u2013 without the victim ever opening them. In the demo, Copilot swapped bank details in payment instructions and presented a fake Microsoft login page.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n \u201cThe BSI recommends conducting a risk analysis for the specific use case before integrating large language AI models into workflows.\u201d<br \/>\n<cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">&#8211; BSI, Generative AI Models: Opportunities and Risks, paraphrased (May 2024)<\/cite>\n<\/p><\/blockquote>\n<h2>Oversharing: The underestimated everyday risk<\/h2>\n<p>The spectacular vulnerabilities dominate the headlines. Yet the biggest Copilot risk is mundane: <strong>excessive permissions in SharePoint, OneDrive and Teams.<\/strong> Microsoft itself identifies oversharing as the most common risk category in Copilot deployments.<\/p>\n<p>The issue: Copilot leverages the existing permission model. If a SharePoint folder was shared via an \u201cAnyone\u201d link, if orphaned workspaces still carry active permissions, if nested group permissions grant access to data the user never consciously saw \u2013 Copilot instantly makes all of it searchable and summarizable.<\/p>\n<p>Take this example: an employee asks Copilot, \u201cWhat was discussed about Project Alpha last week?\u201d Copilot scans every Teams chat, email and SharePoint document the user can access \u2013 including channels they never visited and folders they never opened. When permissions are too permissive, Copilot surfaces confidential information the user would never have found without it.<\/p>\n<p>For German companies this is especially explosive. Unlike in the U.S., where data access within a company is often handled liberally, the GDPR imposes strict requirements on purpose limitation and data minimization. If Copilot summarizes salary negotiations from an HR channel for a marketing employee because Teams permissions were too broad, that is not merely a security problem \u2013 it is a GDPR violation. Bavarian and North Rhine-Westphalia regulators have already signaled that AI-assisted data processing will receive special scrutiny.<\/p>\n<p>Microsoft\u2019s own recommendation is unambiguous: before rolling out Copilot, clean up the permission model. The Oversharing Assessment Blueprint calls for enforcing least-privilege principles, regular permission reviews and SharePoint Advanced Management to identify risky sites. In practice, that means weeks to months of prep work before the first user should activate Copilot.<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:12px;margin:32px 0;\">\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">34 %<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">of German employees use AI outside IT oversight<\/div>\n<\/p><\/div>\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">23 %<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">of German companies have AI policies<\/div>\n<\/p><\/div>\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">40 %<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">of firms expect an AI breach by 2027<\/div>\n<\/p><\/div>\n<\/div>\n<div style=\"text-align:center;font-size:12px;color:#888;margin-top:-20px;margin-bottom:24px;\">Sources: Bitkom 2024, Gartner 2025<\/div>\n<h2>EDPS Ruling: When the European Commission Itself Violates Data Protection Law<\/h2>\n<p>On 8 March 2024 the European Data Protection Supervisor (EDPS) officially determined that the European Commission breached EU data-protection Regulation 2018\/1725 when deploying Microsoft 365. The core findings: insufficient specification of which personal data Microsoft collects and for what purposes, and a lack of adequate safeguards for transfers outside the EU\/EEA.<\/p>\n<p>The sanction was drastic: from 9 December 2024 all transfers of data to Microsoft outside the EU\/EEA had to be suspended. The European Commission has since remedied the breaches \u2013 the EDPS closed the investigation in July 2025 \u2013 but the ruling remains a precedent. If the Commission itself can fall foul of data-protection rules with Microsoft M365, what does that mean for a mid-sized company running the same software with far fewer resources?<\/p>\n<p>For DACH enterprises this is a concrete call to action. A data-protection impact assessment under Article 35 GDPR is strongly advised whenever Copilot is used, according to privacy lawyers. Microsoft has announced in-country data processing for Germany by November 2025, yet whether this fully dispels GDPR concerns is hotly debated among legal scholars.<\/p>\n<p>In November 2025 the BSI issued a specific warning on \u201cevasion attacks on AI language models.\u201d Recommendations include precise system prompts, filtering harmful content in third-party documents, and explicit user confirmation before any action an LLM executes. CERT-Bund has published Advisory WID-SEC-2025-1746 on M365 Copilot. For organisations subject to NIS2 or critical-infrastructure rules, these BSI recommendations are not optional \u2013 they form part of the duty of care whose breach can trigger personal liability for managing directors.<\/p>\n<h2>Shadow AI: The Problem Growing Faster Than Policy<\/h2>\n<p>While IT departments deliberate Copilot roll-outs, employees have long taken matters into their own hands. According to Bitkom, <strong>34 percent of German employees<\/strong> use generative AI tools with private accounts outside corporate IT. In 8 percent of companies shadow AI is widespread \u2013 a doubling versus last year \u2013 and only 23 percent of firms have defined rules for AI use.<\/p>\n<p>Globally the picture is no brighter: a WalkMe survey of 12,000 knowledge workers found 60 percent use AI tools at work, yet only 18.5 percent know of an official AI policy from their employer. Thirty-eight percent share confidential data with AI platforms without approval.<\/p>\n<p>Gartner forecasts that by 2030 more than <strong>40 percent of global companies<\/strong> will experience security or compliance incidents caused by unauthorised AI tools. The 2027 outlook is sharper: 40 percent of all AI data-protection breaches will stem from cross-border misuse of generative AI.<\/p>\n<h2>Why Copilot Is More Dangerous Than ChatGPT<\/h2>\n<p>Many companies equate Copilot with ChatGPT \u2013 a chatbot for writing texts. That\u2019s a fundamental misunderstanding. ChatGPT works with the data the user enters. Copilot works with <strong>all data the user has access to<\/strong> \u2013 plus all data in shared resources they could theoretically access.<\/p>\n<p>The practical difference: if an employee feeds ChatGPT an internal document, that\u2019s a conscious decision \u2013 problematic, but understandable. When Copilot autonomously scans emails, aggregates Teams chats, and summarizes SharePoint documents, it does so automatically and invisibly. Users often don\u2019t even know which sources Copilot uses to assemble its answers.<\/p>\n<p>This has consequences for the attack surface. With ChatGPT, an attacker must trick the user into submitting a manipulated prompt. With Copilot, it\u2019s enough to send a tampered email or drop a doctored file into a shared folder. Copilot pulls the content on its own \u2013 that\u2019s the mechanism the Zenity CTO demonstrated at Black Hat and which Johann Rehberger refined with ASCII Smuggling.<\/p>\n<p>For security teams, this means: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/adaptive-mfa-2026-how-risk-based-authentication-replaces-standard-mfa\/\">threat modeling for Copilot is fundamentally different<\/a> than for other AI tools. Training users isn\u2019t enough. You must secure the entire data landscape \u2013 because Copilot will find every gap and serve it to the user on a silver platter.<\/p>\n<p>Microsoft recognized this and since late 2025 has offered in-country data processing for 15 countries, including Germany. That partially solves the data-transfer issue. But it doesn\u2019t fix the oversharing problem or prevent prompt-injection attacks that occur within the tenant\u2019s own boundaries.<\/p>\n<h2>What you must do before rolling out Copilot<\/h2>\n<p><strong>1. Permission audit before rollout.<\/strong> <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/nis2-registration-requirement\/\">Microsoft recommends SharePoint Advanced Management<\/a> for systematic permission reviews. Eliminate \u201canyone\u201d links, identify orphaned workspaces, and flatten nested group permissions. No Copilot access without a completed permission audit.<\/p>\n<p><strong>2. Deploy sensitivity labels everywhere.<\/strong> Apply Microsoft Purview Information Protection labels to every document and e-mail. Without labels there is no effective DLP control \u2013 and Copilot ignores anything that isn\u2019t labeled.<\/p>\n<p><strong>3. Configure DLP policies for Copilot.<\/strong> Since 2025 Microsoft Purview DLP explicitly supports the location \u201cMicrosoft 365 Copilot.\u201d Skip this step and you unleash Copilot on company data without guardrails.<\/p>\n<p><strong>4. Pilot group before organisation-wide rollout.<\/strong> Limit the initial group to 50 users in a controlled environment. Monitor: which data is Copilot surfacing that it shouldn\u2019t? Only scale once the answer is \u201cnone.\u201d<\/p>\n<p><strong>5. Conduct a GDPR impact assessment.<\/strong> Article 35 GDPR requires a data-protection impact assessment when processing is likely to result in high risks. A KI system that accesses all company data meets this criterion.<\/p>\n<p><strong>6. Establish an AI usage policy.<\/strong> Clear rules: which tools are allowed, which data may be entered, how shadow AI is handled. Bitkom figures show: without a policy, everyone does whatever they want.<\/p>\n<p>The interplay of official Copilot rollouts and unofficial shadow AI creates a double attack surface. On one side, the controlled Copilot instances with their documented vulnerabilities. On the other, uncontrolled private AI tools into which employees feed customer data, contract details, and internal strategy papers \u2013 without audit, logging, or any chance of traceability. For CISOs this is a nightmare scenario: you cannot fully secure either the official or the unofficial AI channel.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n \u201cAI-driven attacks are, according to Gartner, the top emerging risk for companies \u2013 three quarters in a row.\u201d <cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">&#8211; Gartner Q3 2024 Emerging Risks Survey, paraphrased<\/cite>\n<\/p><\/blockquote>\n<p>The crucial point: Copilot is not a security problem per se. It\u2019s a multiplier. Organisations that have their permissions under control benefit. Those that don\u2019t give an AI access to everything that\u2019s poorly secured \u2013 and make it searchable, summarisable, and exportable. Preparing for Copilot isn\u2019t an IT task; it\u2019s a security task.<\/p>\n<p>One final thought for context: Microsoft is not the enemy. Copilot is a productive tool that, with the right preparation, delivers real added value. But preparation is the key \u2013 and most companies underestimate the effort. The EchoLeak vulnerability, the EDPS ruling, and Bitkom\u2019s shadow-AI figures all point the same way: organisations that roll out AI assistants without first putting permissions, data-protection architecture, and usage policies in order are acting negligently. And under NIS2, negligence in IT security can have personal consequences for senior management.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Is Microsoft 365 Copilot unsafe?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Copilot itself isn\u2019t inherently unsafe. It does, however, amplify existing permission problems \u2013 making data accessible that users would never have found without Copilot. Documented vulnerabilities (EchoLeak, ASCII Smuggling, label bypass) have been patched by Microsoft, yet they show the system remains attackable.<\/p>\n<\/details>\n<details>\n<summary><strong>What is EchoLeak (CVE-2025-32711)?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The first documented zero-click vulnerability in a production KI system. CVSS score 9.3 out of 10. Attackers could exfiltrate data from the Copilot context without any user action. Microsoft closed the gap in May 2025.<\/p>\n<\/details>\n<details>\n<summary><strong>What did the EDPS decide about Microsoft 365 usage?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">In March 2024 the European Data Protection Supervisor ruled that the European Commission had violated data-protection law when using M365. The breaches were remediated by July 2025, yet the ruling remains a precedent for every EU organisation using M365.<\/p>\n<\/details>\n<details>\n<summary><strong>Do I Need a GDPR Impact Assessment for Copilot?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Data-protection lawyers strongly recommend conducting a data-protection impact assessment under Art. 35 GDPR, since Copilot processes personal data and has broad access to corporate data. Microsoft\u2019s Data Processing Addendum contains no specific provisions for AI\/Copilot.<\/p>\n<\/details>\n<details>\n<summary><strong>How Widespread Is Shadow AI in German Companies?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">34 percent of German employees use generative-AI tools with private accounts that bypass corporate IT (Bitkom 2024). In 8 percent of firms, shadow AI is already widespread. Only 23 percent have formal rules for AI use.<\/p>\n<\/details>\n<details>\n<summary><strong>What Must I Do Before Rolling Out Copilot?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">At minimum: run a permissions audit in SharePoint, OneDrive and Teams; roll out sensitivity labels enterprise-wide; configure data-loss-prevention (DLP) policies for Copilot; perform a GDPR impact assessment; and establish an AI usage policy. Microsoft advises a pilot test with no more than 50 users.<\/p>\n<\/details>\n<details>\n<summary><strong>Can Copilot Access Confidential E-Mails?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes \u2013 if the permissions allow it. In January 2026 a bug was documented in which Copilot accessed protected e-mails in Sent Items and Drafts despite confidentiality labels. Microsoft issued an emergency patch.<\/p>\n<\/details>\n<div style=\"background:#f0f8ff;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<h2 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">Editor\u2019s Reading List<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/supply-chain-attack-on-trivy-when-the-security-scanner-itself-becomes-a-weapon\/\">Supply-Chain Attack on Trivy: When the Security Scanner Itself Becomes the Weapon<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/19\/identity-attacks-2026-why-hackers-no-longer-break-in-they-log-in\/\">Identity Attacks 2026: Why Hackers Log In Instead of Breaking In<\/a><\/li>\n<li>NIS2 in Germany: What Companies Need to Know Now<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#f0f8ff;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/supply-chain-attack-on-trivy-when-the-security-scanner-itself-becomes-a-weapon\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/supply-chain-angriff-trivy-code-2026-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Trivy Supply-Chain Attack: Scanner Weaponized<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/19\/identity-attacks-2026-why-hackers-no-longer-break-in-they-log-in\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/identity-attacks-login-weapon-250x167.jpeg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Identity Attacks 2026: Logging In<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft 365 Copilot has a zero-click vulnerability rated CVSS 9.3. The European Data Protection Supervisor has reprimanded the EU Commission for its use of M365. And 34 percent of German employees are using AI tools outside the corporate IT. Three facts, one problem: companies are rolling out AI assistants without first building [&hellip;]","protected":false},"author":55,"featured_media":5571,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"copilot","_yoast_wpseo_title":"Copilot as a Security Risk: When the AI Assistant Leaks Corporate Secrets","_yoast_wpseo_metadesc":"Copilot security risk: Zero-click vulnerability (CVSS 9.3) leaks corporate data. Learn how to protect your organization\u2014read now and act today.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5572"],"footnotes":""},"categories":[255,259],"tags":[],"class_list":["post-7736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":14,"wpml_language":"en","wpml_translation_of":5572,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7736","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7736"}],"version-history":[{"count":8,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7736\/revisions"}],"predecessor-version":[{"id":21667,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7736\/revisions\/21667"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5571"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}