Aim Security A.I CyberSecurity Scoring
Aim Security
Company Information
Website:http://www.aimsecurityguards.com
Employees number:23
Number of followers:18
NAICS:92212
Industry Type:Law Enforcement
Homepage:aimsecurityguards.com
Aim Security Risk Score (AI oriented)
Between 750 and 799
Aim SecurityLaw Enforcement
Updated:
30/03/2026
30/03/2026
761/1000
Fair
Baa
Aim Security Global Score (TPRM)
xxxx
Aim SecurityLaw Enforcement
Score locked

Aim SecurityFair
Current Score
761Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
762
MAY 2026
762
APRIL 2026
761
MARCH 2026
761
FEBRUARY 2026
761
JANUARY 2026
761
DECEMBER 2025
761
NOVEMBER 2025
761
OCTOBER 2025
761
SEPTEMBER 2025
760
AUGUST 2025
760
JULY 2025
760
JUNE 2025
770
Vulnerability
11 Jun 2025 • Aim Security
Aim Security: Microsoft 365 Copilot ‘zero-click’ vulnerability enabled data exfiltration
EchoLeak: Zero-Click Flaw in Microsoft 365 Copilot
760
CRITICAL-10
AIM1765254813
Microsoft Patches Critical Zero-Click Flaw in Microsoft 365 Copilot
Microsoft has addressed a severe "zero-click" vulnerability in its Microsoft 365 Copilot AI tool, tracked as CVE-2025-32711 (CVSS 9.3), which could have enabled attackers to exfiltrate sensitive data without user interaction. Discovered by Aim Security and dubbed "EchoLeak," the flaw allowed unauthorized access to a victim’s Outlook emails, OneDrive files, SharePoint sites, and Microsoft Teams chat history via a specially crafted email.
The exploit bypassed multiple security layers, including Copilot’s cross-prompt injection attack (XPIA) classifiers and link redaction protections, by leveraging markdown references and a Microsoft Teams URL proxy endpoint to transmit stolen data to an attacker-controlled server. Unlike traditional phishing attacks, this method did not require the victim to click a malicious link—simply referencing the attacker’s email in a Copilot query could trigger the data leak.
Aim Security demonstrated that attackers could increase the likelihood of exploitation by sending multiple emails on varied topics or a single long, segmented email covering subjects likely to be queried by the victim. While Microsoft confirmed the flaw had not been exploited in the wild, security experts warn that similar vulnerabilities may exist in other retrieval-augmented generation (RAG)-based AI tools, highlighting a broader risk in AI assistant architectures.
The patch resolves the issue, requiring no further user action. However, the incident underscores the need for runtime guardrails, stricter input scoping, and clear separation between trusted and untrusted data in AI systems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Aim Security ??
What was Aim Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Aim Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Aim Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Aim Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Aim Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Aim Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Aim Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Aim Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Aim Security's A.I Rankiteo Cyber Score in September 2025 ??
What was Aim Security's A.I Rankiteo Cyber Score in August 2025 ??
What was Aim Security's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Aim Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Aim Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Aim Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?