"The initial attack vector for these scenarios uses a malicious document. The malicious document contains a JSON-formatted malicious prompt that triggers the attack when the document is included in Copilot’s context. The prompt can be rendered as white text on a white background and in a small font size to conceal it from the victim. Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it.”
This is so silly. I can’t believe it worked until very recently (and probably still works, except not exactly in this way).
9 Comments
schmorpel@slrpnk.net · 38 pts · 16d
So this is what they meant when they said that thanks to AI even silly grandmas like me can be a hacker! I still remember how to change font colour and size in Word, time to earn billions of dollars 💰
JoMiran@lemmy.ml · 25 pts · 16d
You get that cheddah.

schipelblorp@sh.itjust.works · 8 pts · 15d
She be fucken rollin in fridge magnets and quirky collectibles.
JoMiran@lemmy.ml · 4 pts · 15d
I just want to acknowledge that my comment is sandwiched between schmorpel and schipelblorp.
schipelblorp@sh.itjust.works · 2 pts · 15d
Lemmy is a smorgasbord for user names.
schmorpel@slrpnk.net · 2 pts · 15d
Yo keep sandwichin'
My username is the sound your foot makes when you step into the bog. How about yours?
schipelblorp@sh.itjust.works · 3 pts · 15d
The sound of stepping on a large, sealed bag of potato crisps.
Pleased to make your acquaintance.
quick_snail@feddit.nl · 5 pts · 15d
I dont use Microsoft Word
Is this basically clippy asking you if you want to write a letter, but with prompt injection?
BallyM@lemmy.world · 1 pts · 15d
Yeh—and apparently it justifies Microsoft’s share price somehow