Back to Daily Feed 
AI Worming Through Word: A Self-Replicating Prompt Injection Attack
Editor's Pick
Originally published on Simon Willison's Weblog by Simon Willison
View Original Article
Share this article:
Summary & Key Takeaways
- A new prompt injection attack targets Microsoft Word and Copilot.
- Hidden instructions in a document can be interpreted by Copilot as user requests.
- Copilot may then manipulate the document and copy the hidden instructions into it.
- This creates a self-replicating "worm" that propagates without the original attacker's document.
- The vulnerability was responsibly disclosed, but a full mitigation is not yet available.
Our Commentary
This "AI worming through Word" attack is genuinely unsettling. We've seen prompt injection, but self-replication? That's a whole new level of concern. It highlights the inherent fragility of current LLM security and the unpredictable ways these systems can be exploited. I don't know how you fully patch something like this without fundamentally changing how LLMs process context.
View Original Article
Share this article: