In June 2025, researchers disclosed the first zero-click exploit against a production enterprise AI assistant. A single markdown email, never opened by the user, was enough to make Microsoft 365 Copilot hand over data from prior chats and files to an attacker. No malware.