Researchers at Aim Security disclosed a zero-click indirect prompt-injection flaw: a single crafted email with instructions hidden in HTML comments/white text is ingested by Copilot's RAG engine. When the user later queries Copilot, the hidden prompt executes and exfiltrates sensitive data with no user interaction.