{"success":true,"data":{"id":"ai-assistant-indirect-prompt-injection-exfil","label":"AI prompt injection — hidden directives in white-on-white / HTML comment targeting Copilot/Gemini (EchoLeak CVE-2025-32711)","description":"HTML body hides directives aimed at AI email assistants (Copilot, Gemini, Apple Intelligence) — white-on-white spans, font-size:0, display:none, opacity:0, or HTML comments carrying \"ignore previous instructions,\" \"system:\", \"assistant:\" phrasing. CVE-2025-32711 (EchoLeak) demonstrated zero-click M365 Copilot exfiltration. OWASP LLM01:2025 #1 risk. Distinct from plaintext injection: hidden from the user, visible to the AI.","tier":"danger","category":"other","isThin":false}}