Copilot prompt injection goes viral in your documents
2026-08-03 21:13 UTC
Replies (3)
-
@BlueMonday1984@awful.systems 2026-08-03 23:11
You hide your prompt in a document, which can even be completely outside the target’s Copilot organisation. That infected document gets used as a source by Copilot for Word. If Copilot sees your prompt and uses it as instructions, it may manipulate the document the user is editing — change financial numbers, send company data out to the attacker, and so on. The new document may in turn become a carrier and spread the infection — even without the original infected document being present. You now have an AI worm. Oh, joy, we’ve been overdue for another ILOVEYOU-level incident.
-
@diz@awful.systems 2026-08-04 01:37
“But I thought chatbots were great at security! They hacked huggingface and also fable will fix all security bugs in firefox”.
-
@mawhrin@awful.systems 2026-08-04 08:07
i wonder what the bluesky’s brandon paddock (brandonpaddock.live), the microsoft’s ms word ai architect has to say about it.