Fixed and fixed properly
This is interesting.
'Exclusive' article on Fortune today explaining how researchers discovered a zero-click attack on MS Copilot which starts with sending an email with hidden instructions (prompt injection). Microsoft have definitely fixed it though
(https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/)
BUT, because I have a memory