Copilot has the largest AI attack surface of any tool we tracked

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Industry News, Awareness

Copilot has the largest AI attack surface of any tool we tracked

Used the least. Installed on the most.

September 29, 2026

Microsoft Copilot accounts for a disproportionate share of the AI footprint we track, and it’s barely being used. It’s a massive attack surface featuring a minuscule rate of activity.

Our AI visibility tool tracks dozens of AI tools running across the endpoints in its install base. Among the five most common, Copilot accounts for 57% of the footprint, more than the share of the other four tools combined (43%). Its activity per device, 15.2 events per endpoint, is the lowest of the five.

Every tool on every endpoint is a potential attack surface, and every IT team in every business must balance the usefulness of the tool against the vigilance and effort it takes to secure it. The last thing any organization needs is a tool with an inscrutable attack surface, installed on every endpoint, that relatively few utilize — and that criminals are showing a growing appetite for.

Copilot often ships bundled inside Microsoft 365 plans, which is likely why so much of that footprint sits unused: a device can have it installed the moment a company buys the suite, whether or not anyone ever actually wants or uses it. Counting installs measures procurement, not adoption.

For a team sizing up the attack surface it has to defend, that scale is the point: a tool that accounts for more than half of the total footprint across these five tools, and is barely touched, carries a very different risk profile than a tool with a fraction of that footprint used constantly.

This isn’t a hypothetical category of risk, either. In June 2025, researchers disclosed EchoLeak, a zero-click vulnerability in Microsoft 365 Copilot that let an attacker pull emails, OneDrive files, and SharePoint content out of a target’s environment using a single crafted email and no user interaction whatsoever. It’s tracked as CVE-2025-32711, with a Critical severity score of 9.3 out of 10. Microsoft patched it before the research went public, with no evidence it was ever exploited in the wild, but the point is clear: AI assistants with broad access to corporate data are now a standing target for researchers trying to anticipate cybercriminals’ next wave of targets.

No place for passengers

Late last month, Microsoft joined more than 120 companies, including OpenAI, Google, Anthropic, AWS, and CrowdStrike, in signing an open letter calling for a coordinated response to AI-powered cyberattacks. Its central argument: “Recognize that status quo security won’t be enough.” Microsoft signed that warning while running exactly the kind of deployment it describes: an AI tool installed everywhere and used almost nowhere.

As organizations start taking that warning seriously, every application already sitting in the stack will have to earn its place harder than it used to. There’s simply no room left for passengers.

Thankfully, there’s already a practical answer, at least for this one. A Windows update this year gave IT admins the “Remove Microsoft Copilot App” policy: it does exactly as it says. It strips Copilot off of eligible devices where the app was never installed by the user and hasn’t been opened in the last 28 days. It won’t fix every unused AI tool sitting in a stack, but it’s a real lever for this one.

Microsoft 365 AI security Microsoft Copilot attack surface EchoLeak CVE-2025-32711 AI risk endpoint security

The post Copilot has the largest AI attack surface of any tool we tracked appeared first on ThreatDown.

Article Link: Copilot has the largest AI attack surface of any tool we tracked | ThreatDown