Knowledge File / AI小生意项目库
安全研究员构建自我传播蠕虫,藏身Word文档并劫持Microsoft Copilot
Håkon Måløy展示针对Copilot for Word的提示注入攻击,文档中隐藏指令可自行传播,微软确认后修复失败。
SOURCE / AI小生意项目库
MIN / 9
ACCESS / 会员
POST / 2026-08-01 21:51:57
原贴
查看原文原文
A security researcher has shown how a prompt injection attack in Microsoft Copilot for Word can spread on its own. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document using white text on white background at tiny font size. Readers can't see it but Copilot can, since it strips color and font size before processing. When someone uses that document as a source, Copilot runs the hidden instructions and copies them into the new file. That file becomes a carrier. Use it as a template, and the attack fires again. A compromised market analysis from the internet could manipulate a financial report, which then infects further reports. Microsoft confirmed the behavior on March 31. Two fix attempts failed. After 144 days, Måløy published his findings with no fix in place, though he's holding back the payload text. AI researcher Andreas Kirsch recently joked he wished someone would build exactly this worm to convince skeptics that AI security risks are real. Now it exists. Prompt injections remain an unsolved AI security problem . Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
中文翻译
一位安全研究人员展示了如何利用Microsoft Copilot for Word中的提示注入攻击自行传播。Håkon Måløy描述了一种类似蠕虫的攻击方式:攻击者使用白色字体、白色背景、极小字号在文档中隐藏指令。读者看不到,但Copilot能看到,因为它在处理前会去除颜色和字号。当有人将该文档用作源时,Copilot会运行隐藏指令并将其复制到新文件中。该文件就成为载体。将其用作模板,攻击就会再次触发。来自互联网的受感染市场分析可能操纵财务报告,进而感染更多报告。微软于3月31日确认了该行为。两次修复尝试均失败。144天后,Måløy在没有修复的情况下发布了其发现,不过他保留了有效载荷文本。AI研究员Andreas Kirsch最近开玩笑说,他希望有人能构建出这样的蠕虫,以说服怀疑者AI安全风险是真实存在的。现在它存在了。提示注入仍然是一个未解决的AI安全问题。订阅THE DECODER以获取无广告阅读、每周AI通讯、每年六次独家“AI Radar”前沿报告、完整存档访问权限以及评论区的访问权限。
核心信息
Håkon Måløy展示针对Copilot for Word的提示注入攻击,文档中隐藏指令可自行传播,微软确认后修复失败。
- Håkon Måløy展示针对Copilot for Word的提示注入攻击,文档中隐藏指令可自行传播,微软确认后修复失败。
- 原贴提到:A security researcher has shown how a prompt injection attack in Microso
- 来源:the-decoder.com
试看内容
成为会员查看完整内容
你已经看到了这篇内容的前置整理,剩余深度部分仅对会员开放。
详细解读
信息差价值
参考来源
成为会员查看完整内容