安全研究员展示利用Word文档传播的Copilot蠕虫攻击
原标题:A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
AI 摘要
安全研究员Håkon Måløy开发了一种利用Microsoft Copilot for Word的提示注入漏洞的自传播蠕虫。该蠕虫通过隐藏在白底白字中的指令,在文档处理时被Copilot执行并复制到新文件中,从而实现传播。微软于3月31日确认此行为,但两次修复尝试均失败,144天后研究员公开了发现,但未提供修复方案。此事件凸显了提示注入作为AI安全问题的未解决性。
正文节选
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot A security researcher has shown how a prompt injection attack in Microsoft Copilot for Word can spread on its own. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document using white text on white background at tiny font size. Readers can't see it but Copilot can, since it strips color and font size before processing. When someone uses that document as a sour