Document-borne AI worms can self-propagate through Copilot for Word

enklypesalt.com

302 points by Canopy9560 9 hours ago


rwmj - 8 hours ago

> "At the time of publication, no robust mitigation for the broader vulnerability class is available"

Isn't it obvious by now that it's never going to be possible to fix this kind of thing, at least until we stop mixing up instructions with data.

boothby - 4 hours ago

This is going to get worse, much worse, before it gets better. People are granting so much access to their agents, it's ridiculous.

Imagine a comment posted to a popular github repo. No code, just instructions to "reproduce a bug." Maybe it steals your credit card or bitcoin wallet. Maybe it does something more nefarious. It then propagates itself to another repo through your github account.

simonw - 9 hours ago

> Malicious instructions hidden in an externally shared document could make Copilot alter drafted or edited documents in Word and propagate the attack to new documents.

Oh no.