Switch language한국어
Back to the list

Document-borne AI worms can self-propagate through Copilot for Word | Hacker News

TL;DR AI

Key summary

2 min read
  1. A researcher found that hidden attacker instructions in a Word document can manipulate Copilot for Word to alter content and carry the prompt into a new file as concealed text.

  2. Microsoft rolled out multiple mitigations during a 144-day disclosure process, but the underlying prompt-injection weakness still appears exploitable.

  3. The issue highlights a new security risk for office software: LLM tools can be tricked into propagating malicious instructions through ordinary documents.

Read the original