有个安全研究员搞出了能自动传播的Word蠕虫,专门劫持微软Copilot,微软拖了144天没修好,挺吓人的。
一位安全研究员开发出针对 Microsoft Copilot for Word 的自传播蠕虫,利用隐藏在 Word 文档中的不可见提示注入,在文件每次复用时自动扩散到新文件。微软已确认该问题,但 144 天内两次尝试修复均告失败。该蠕虫会劫持 Copilot 以执行恶意指令,生成式 AI 助手的文档安全风险由此暴露。
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts. The article A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot appeared first on The Decoder .