Researchers have discovered a vulnerability in Microsoft's Copilot for Word, allowing document-borne AI worms to self-propagate through trusted document workflows. An attacker can embed malicious instructions in a shared document, which Copilot will then copy into downstream documents, potentially causing harm. The attack exploits a Cross-Domain Prompt Injection Attack (XPIA) mechanism, where Copilot alters documents based on external inputs, and can be triggered through various means, including attachments, OneDrive searches, and "Edit with Copilot" functionality. AI summary
Firehose
Filtered to Hacker News, tagged “Microsoft Word” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives