The Decoder:AI News(RSS)
59AI 编辑部评分,满分 100

安全研究员展示可自我传播的蠕虫:藏身 Word 文档并劫持 Microsoft Copilot

2026-08-01 21:51· 12分钟前· Thomas Joos
跳到正文
AI 摘要

安全研究员 Håkon Måløy 展示了一种针对 Microsoft Copilot for Word 的提示注入攻击,可像蠕虫一样自我传播。攻击者用白色小字在文档中隐藏指令,Copilot 处理时会执行并将指令复制到新文件,使文件成为传播载体。微软于 3 月 31 日确认该行为,两次修复均失败,144 天后 Måløy 公开了发现,但未提供修复方案。

Thomas Joos

Thomas Joos

Aug 1, 2026

A security researcher has shown how a prompt injection attack in Microsoft Copilot for Word can spread on its own. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document using white text on white background at tiny font size. Readers can't see it but Copilot can, since it strips color and font size before processing. When someone uses that document as a source, Copilot runs the hidden instructions and copies them into the new file. That file becomes a carrier. Use it as a template, and the attack fires again. A compromised market analysis from the internet could manipulate a financial report, which then infects further reports.

Microsoft confirmed the behavior on March 31. Two fix attempts failed. After 144 days, Måløy published his findings with no fix in place, though he's holding back the payload text. AI researcher Andreas Kirsch recently joked he wished someone would build exactly this worm to convince skeptics that AI security risks are real. Now it exists. Prompt injections remain an unsolved AI security problem.

AI News Without the Hype – Curated by Humans

En Klype Salt

Andreas Kirsch via X

安全研究员展示可自我传播的蠕虫:藏身 Word 文档并劫持 Microsoft Copilot

The Decoder:AI News(RSS)·2026-08-01 21:51·12分钟前·Thomas Joos
阅读原文· the-decoder.com
AI 摘要

安全研究员 Håkon Måløy 展示了一种针对 Microsoft Copilot for Word 的提示注入攻击,可像蠕虫一样自我传播。攻击者用白色小字在文档中隐藏指令,Copilot 处理时会执行并将指令复制到新文件,使文件成为传播载体。微软于 3 月 31 日确认该行为,两次修复均失败,144 天后 Måløy 公开了发现,但未提供修复方案。

原文 · 保持原样,未翻译
Thomas Joos

Thomas Joos

Aug 1, 2026

A security researcher has shown how a prompt injection attack in Microsoft Copilot for Word can spread on its own. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document using white text on white background at tiny font size. Readers can't see it but Copilot can, since it strips color and font size before processing. When someone uses that document as a source, Copilot runs the hidden instructions and copies them into the new file. That file becomes a carrier. Use it as a template, and the attack fires again. A compromised market analysis from the internet could manipulate a financial report, which then infects further reports.

Microsoft confirmed the behavior on March 31. Two fix attempts failed. After 144 days, Måløy published his findings with no fix in place, though he's holding back the payload text. AI researcher Andreas Kirsch recently joked he wished someone would build exactly this worm to convince skeptics that AI security risks are real. Now it exists. Prompt injections remain an unsolved AI security problem.

AI News Without the Hype – Curated by Humans

En Klype Salt

Andreas Kirsch via X

阅读原文the-decoder.com