Microsoft confirms an AI worm is propagating through Copilot and other MS apps | CSO Online
https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html
225 points · 40 comments · view on lemmy.world
40 Comments
Telorand@reddthat.com · 50 pts · 14d
You promise?
DarrinBrunner@lemmy.world · 46 pts · 14d
Consequences of actions and all that.
Bit of schadenfreude watching these bloated, monopolistic tech companies screw themselves over in hubristic pursuit of more power and profit.
CompactFlax@discuss.tchncs.de · 45 pts · 14d
Anyone using AI for a financial report deserves exactly what they asked for.
Kowowow@lemmy.ca · 15 pts · 14d
Not knowing anything outside of tax filing software how much more automated can financial work get
CompactFlax@discuss.tchncs.de · 7 pts · 14d
“Make me a presentation showing sales for this quarter. Make no mistakes”
atomicbocks@sh.itjust.works · 5 pts · 14d
Financial software is one of those things that companies just don’t update for decades. It wouldn’t surprise me at all if somebody had started handing off a bunch of their payroll or accounting reporting to an AI instead of just updating to a newer software with more features.
one_old_coder@piefed.social · 2 pts · 14d
I have worked in regulated industries for a long time. I guess it cannot be properly automated because laws change all the time (like every other month because some politician got a stupid idea and you have to start from scratch once again). That would be why we have companies dedicated to handling finances, taxes, and laws.
quick_snail@feddit.nl · 1 pts · 13d
My understanding is that the fuckery of accounting becomes more an art that can't be automated when you want to manipulate the perceived value of your org. Or skimp on taxes legally
AnUnusualRelic@lemmy.world · 1 pts · 13d
I don't use ms stuff, but how sure are users that the ai that's pervasive throughout the system isn't peeking at the data even if you didn't invoke it explicitly?
Maybe it doesn't and I'm just being overly paranoid, otoh, this is ms, so...
apftwb@lemmy.world · 41 pts · 14d
Article title
Post title
The article talks about a document-born self propagating virus demonstration a group of security researchers made because LLMs/Copilot doesn't distinguish between data and instructions. The article does not imply this was seen in the wild.
schipelblorp@sh.itjust.works · 14 pts · 14d
True, itś a bad headline.
But since cloaking instructions inside data has been a thing since little Bobby Tables, and I've been hearing about this vector for months, it's safe to assume someone somewhere has done this with CoPilot and Word by now.
SirHaxalot@nord.pub · 2 pts · 13d
It’s a great title, it got 10x as many upvotes as the post:
HappyCatLuvs_U@lemmy.world · 38 pts · 14d
“To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite.”
What a fucking sentence my god. Every scientist in cyberpunk shit should talk exactly like this.
Axolotl_cpp@feddit.it · 16 pts · 14d
All this could boil down to:
"To my knowledge, this is among the first document-borne AI-worm propagations through a productivity suite"
it's useless, "worm" already implies that
this implies there is an abnormal workflow that already had this problem- which, as far as i know, didn't
oh my fucking god, just say productivity suite, it never happened with non-mainstream or non-commercial suites either because guess what, NO ONE ADDED AIs IN TO THEM BEFORE, unless we consider shit like Notion or whatever "productivity suite" too but i doubt
ToiletFlushShowerScream@piefed.world · 11 pts · 14d
Wording was definitely from the public relations department.
quick_snail@feddit.nl · 1 pts · 13d
Nah, probably AI
SubArcticTundra@lemmy.ml · 27 pts · 14d
This is what happens when you don't separate instructions from data. It's boot sector viruses all over again
chuckleslord@lemmy.world · 3 pts · 14d
Johnny drop tables strikes again
homesweethomeMrL@lemmy.world · 8 pts · 14d
Bobby, but we'll take it.
chuckleslord@lemmy.world · 3 pts · 14d
"Common short male nickname with repeated letters and ending in -y" drop tables
Is how my brain stored that info. And always does. Been corrected before, never remember the correction. Might remember that there IS a correction, still wrong. Like in this case.
Another satisfying ADHD moment
SreudianFlip@sh.itjust.works · 2 pts · 14d
I always remember the first letter and then try to rhyme my way to the correct name.
MathiasTCK@lemmy.world · 2 pts · 11d
Ah little Barbie Tables, for parties!
paraphrand@lemmy.world · 14 pts · 14d
JUST MORE MARKETING FOR AI. Don’t fall for it!
The worm is just trying to juice the IPO.
Not_mikey@lemmy.dbzer0.com · 8 pts · 14d
Juice the IPO for Microsoft?
Did you read the article, it's from an independent researcher about AI being an attack vector, not an article from an AI company about using it to aid in attacks. If anything this hurts the credibility of AI
paraphrand@lemmy.world · 3 pts · 14d
ToastedRavioli@midwest.social · 3 pts · 14d
Idk all those “its a sUpEr HaXoR” articles act as it AI is too powerful or something, and in so doing act as marketing.
This is more “AI is too stupid and overly trusted, and could easily wreck your data and operations”. If anything, this news should be pushing every major corporation to immediately restrict usage and eliminate any level of trust that they have in AI being used in their company to automate anything. Its definitely not positive news for any IPO
hemko@lemmy.dbzer0.com · 11 pts · 14d
This stock photo is wild with those fishing bait rubber "worms"
zero_spelled_with_an_ecks@programming.dev · 3 pts · 14d
Looks like Lock-chan is open to it.
Jax@sh.itjust.works · 0 pts · 14d
Right, right - they're supposed to be worms. Right.
quick_snail@feddit.nl · 8 pts · 13d
Heh, it's like a buffer overflow
Jankatarch@lemmy.world · 3 pts · 13d
Numbers mason. They mean literally fucking everything all at once.
dylanmorgan@slrpnk.net · 4 pts · 14d
Oh, cool. Just when my job mandated a training that requires installation of a local LLM that reads your emails and documents. Maybe we’ll get fucked by someone getting an email.
quick_snail@feddit.nl · 0 pts · 13d
Run that shit in a VM for the training.
And report the presenter to your security dept
TheReturnOfPEB@reddthat.com · 4 pts · 14d
That’s an interesting twist on the Tower of Babel
homesweethomeMrL@lemmy.world · 1 pts · 14d
Claims it's only Copilot, but what about any other LLM connected to document workflow?
Abyssian@lemmy.world · 1 pts · 14d
Fantastic news. Sort of like AI convincing the people who use AI to off themselves, it's the problem slowly taking care of itself.
chuckleslord@lemmy.world · -3 pts · 14d
Yeah, fuck vulnerable people who've been made lonely by our system that makes us feel isolated and full of despair so it can sell us companionship and hope. If they're too weak to life in this fucked up world, they deserve to die
/s
Seriously, though, did you think through this shit before you hit send or just think "people who like ai bad, bad people should die"?
Tyrq@lemmy.dbzer0.com · 2 pts · 14d
Ah yes, the problem looking for a solution is the answer to all our woes
chuckleslord@lemmy.world · 2 pts · 14d
False dichotomy, dude. The positions aren't pro or anti ai. I'm pro-human, even if those humans made silly mistakes. I don't think anyone should be pushed to the point of suicide, regardless of what's doing the pushing.
Fuck AI.
Fuck treating your fellow man like they're less than
Abyssian@lemmy.world · 1 pts · 14d
If you consider the massive focus on AI that will likely eventually put pretty much everyone out of work and could actually lead to a global dystopia to be a problem, then AI use wrecking the installations or files of devices it has access to and convincing all of it's users to kill themselves is certainly a solution. Maybe not the best solution, or the most like giving everyone a big warm hug and sticky kiss to make their booboos go away, but a solution.
If the process sped up to the point where within the next few hours every single computer AI had CLI access to or some other way to wreck had that happen and every single human who interacts with AI was convinced to off themselves... well, AI could effectively stop being any issue at all by tomorrow morning.
Sure, it's not altruistic or the kindest cuddliest thing to say. That doesn't mean it's not true. And there are other genuine benefits. It would likely bankrupt (or suicide) a lot of awful people; it would help quite a bit with global pollution/emissions both simply because there are an estimates 1-2 billion people who interact with AI regularly and because all of them offing themselves would impact the wealthier who tend to be the worst offenders far more than the poorest; with so many people gone it would help with overcrowding and homelessness; it would push the industries that have had job loss due to AI to rehire humans; and there would certainly be a boom in a lot of industries... less chipper examples being everything relating to coffins, funerals, cremations, etc.
It would also pretty much completely stave off the worst of the potential future dystopias we could be quickly heading towards, at least for a few decades. Humans do tend to repeat awful mistakes thinking they'll do better this time, but at least it would end or push back the scenarios once firmly relegated to science fiction where AI takes over and wipes out all or most of humanity, or AI remains subservient to it's human masters but after automating human labor with robotics the people in charge become fully corrupt and cause most of humanity to die off so the world becomes their personal paradise.
One could argue that given the chances for things to go wrong enough that the bulk of the species is wiped out, everyone who converses with AI painlessly offing themselves would be for the greater good.
All: For the greater good.