i wonder what the bluesky's brandon paddock (brandonlive.com), the microsoft's ms word ai architect has to say about it.
post
You hide your prompt in a document, which can even be completely outside the target’s Copilot organisation. That infected document gets used as a source by Copilot for Word. If Copilot sees your prompt and uses it as instructions, it may manipulate the document the user is editing — change financial numbers, send company data out to the attacker, and so on.
The new document may in turn become a carrier and spread the infection — even without the original infected document being present. You now have an AI worm.
Oh, joy, we've been overdue for another ILOVEYOU-level incident.
"But I thought chatbots were great at security! They hacked huggingface and also fable will fix all security bugs in firefox".
all 3 comments