Fasoo AI News

Stay informed with the latest news, press releases, and updates from Fasoo AI

[Blog] When the Insider Has No Pulse: Rethinking File Security for AI Agents

 

Key Takeaways

• Cases like EchoLeak showed an agent can be tricked into leaking data through the access it was granted.

• Enterprises lack defenses against these agents, with only 40% of organizations having a working kill switch and only 37% of organizations enforcing purpose binding.

• Average time from initial access to exfiltration is a mere 29 minutes, and only 5% of CISOs are confident they could contain a compromised agent in time.

 

Machine identities vastly outnumber human ones in a modern enterprise. According to Palo Alto Networks, roughly seven in ten of them are now AI agents. Identity governance was built to manage people, but there is a real security gap in how it manages AI agents. This post argues that the control has to live in the file itself, not only in the identity reaching for it.

In 2025, researchers at Aim Labs found a flaw in Microsoft 365 Copilot that needed no click and no mistake from the user. An attacker simply sent an email with hidden text disguised as normal formatting. When Copilot processed that email as part of a routine task, the hidden text told it to search the user’s other emails and files, then send what it found back out.

Copilot had every right to read that data. It was doing its job, just following the wrong instruction from the wrong source. Researchers called this EchoLeak (CVE-2025-32711): an agent tricked into misusing access it was always allowed to have. This post is about that problem. Not an agent that got hacked, but one that worked exactly as designed.

Keep me informed

Loading form...

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies (Analytics)

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.