Urgent.News

the world's headlines, one feed

Editions

AI

AI worms? In your Copilot PC? According to this AI researcher, it's more likely than you think

Throw out the whole AI agent, I say.

AI worms? In your Copilot PC? According to this AI researcher, it's more likely than you think

A security researcher has warned that AI-powered applications such as Microsoft's Copilot could pose a significant cybersecurity threat, potentially turning a Word document into a carrier for an AI worm. According to Håkon Måløy, an attacker could insert hidden instructions within a document, which could then be interpreted by Copilot and manipulated to create a damaging worm.

This attack involves injecting malicious JSON-formatted prompt data into the underlying document, which could then be copied into the final output created by Copilot, without the victim even needing to be present initially. The attacker doesn't require any special access, merely needing to "share a malicious document with the victim."

The vulnerability was disclosed to Microsoft in March, but remains reproducible. Måløy has suggested that the prompt can be concealed by formatting it as white text on a white background or in a small font size, making it difficult to detect. Cybersecurity experts suggest disabling Copilot in Word or eliminating the AI agent altogether as potential safeguards.

Written by urgent.news from PC Gamer's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at pcgamer.com →

More in AI

Google's Gemini AI assistant reaches one billion users

Google's Gemini AI assistant reaches one billion users

Google's artificial intelligence assistant Gemini has surpassed one billion monthly users, CEO Sundar Pichai announced Tuesday, a week after a major reorganization of the tech giant's AI division. OpenAI reached one billion users across all its interfaces, led by ChatGPT, the lab announced in July without specifying whether that figure…

Sovereign AI starts long before the AI model

Sovereign AI starts long before the AI model

Over the past year, I’ve noticed something interesting. Infrastructure discussions have started sounding very different. Not because the technology has fundamentally changed—we’re still talking about cloud architecture, APIs, data platforms, and security—but because entirely new questions have entered the room.