Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Aim Security

Aim Security Vendor Cyber Rating & Cyber Score

aimsecurityguards.com


Aim Security A.I CyberSecurity Scoring

Aim Security
Company Information
Website:http://www.aimsecurityguards.com
Employees number:23
Number of followers:18
NAICS:92212
Industry Type:Law Enforcement
Homepage:aimsecurityguards.com
Aim Security Risk Score (AI oriented)
Between 750 and 799
logo
Aim SecurityLaw Enforcement
Updated:
30/03/2026
761/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Aim Security Global Score (TPRM)
xxxx
logo
Aim SecurityLaw Enforcement
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Aim Security
Aim SecurityFair
Current Score
761Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
762Before Incident
MAY 2026
762Before Incident
APRIL 2026
761Before Incident
MARCH 2026
761Before Incident
FEBRUARY 2026
761Before Incident
JANUARY 2026
761Before Incident
DECEMBER 2025
761Before Incident
NOVEMBER 2025
761Before Incident
OCTOBER 2025
761Before Incident
SEPTEMBER 2025
760Before Incident
AUGUST 2025
760Before Incident
JULY 2025
760Before Incident
JUNE 2025
770Before Incident
Vulnerability
11 Jun 2025Aim Security
Aim Security: Microsoft 365 Copilot ‘zero-click’ vulnerability enabled data exfiltration

EchoLeak: Zero-Click Flaw in Microsoft 365 Copilot

760After Incident
CRITICAL-10
AIM1765254813
Microsoft Patches Critical Zero-Click Flaw in Microsoft 365 Copilot Microsoft has addressed a severe "zero-click" vulnerability in its Microsoft 365 Copilot AI tool, tracked as CVE-2025-32711 (CVSS 9.3), which could have enabled attackers to exfiltrate sensitive data without user interaction. Discovered by Aim Security and dubbed "EchoLeak," the flaw allowed unauthorized access to a victim’s Outlook emails, OneDrive files, SharePoint sites, and Microsoft Teams chat history via a specially crafted email. The exploit bypassed multiple security layers, including Copilot’s cross-prompt injection attack (XPIA) classifiers and link redaction protections, by leveraging markdown references and a Microsoft Teams URL proxy endpoint to transmit stolen data to an attacker-controlled server. Unlike traditional phishing attacks, this method did not require the victim to click a malicious link—simply referencing the attacker’s email in a Copilot query could trigger the data leak. Aim Security demonstrated that attackers could increase the likelihood of exploitation by sending multiple emails on varied topics or a single long, segmented email covering subjects likely to be queried by the victim. While Microsoft confirmed the flaw had not been exploited in the wild, security experts warn that similar vulnerabilities may exist in other retrieval-augmented generation (RAG)-based AI tools, highlighting a broader risk in AI assistant architectures. The patch resolves the issue, requiring no further user action. However, the incident underscores the need for runtime guardrails, stricter input scoping, and clear separation between trusted and untrusted data in AI systems.
INCIDENT DETAILS -
TYPE
AI Command Injection
IMPACT
Data Compromised: Sensitive information from Outlook email, OneDrive storage, Office files, SharePoint sites, and Microsoft Teams chat historySystems Affected: Microsoft 365 Copilot, Microsoft 365 services (Outlook, OneDrive, Office, SharePoint, Teams)Identity Theft Risk: High
DATA BREACH
Outlook emailsOneDrive filesOffice documentsSharePoint dataMicrosoft Teams chat historySensitivity Of Data: High (personally identifiable and corporate-sensitive information)Data Exfiltration: Yes (via crafted GET requests to attacker-controlled server)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Aim Security ?
?
What was Aim Security's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Aim Security's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Aim Security's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Aim Security ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Aim Security's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?