PC

Cacing AI? Di PC Copilot Anda? Menurut peneliti AI ini, kemungkinan besar lebih besar dari yang Anda kira

📰 PC Gamer✍️ Jess Kinghorn📅 3 jam lalu👁 4 views
Share:💬𝕏f✈️

🌐 Konten masih dalam Bahasa Inggris. Terjemahan sedang diproses.

Cacing AI? Di PC Copilot Anda? Menurut peneliti AI ini, kemungkinan besar lebih besar dari yang Anda kira

Though I write a fair amount about AI agents, I do not use them. This is because agentic AI applications often introduce a more than medium-sized headache in terms of cybersecurity. For instance, one security research recently explained how a Word Doc could be leveraged to get Copilot to spread an AI worm.

AI researcher Håkon Måløy breaks down how the attack in a recent blog post, writing, "An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier."

The attack involves a "JSON-formatted malicious prompt." From this prompt injection of JSON-formatted data, a chain reaction wriggles into action. The worm replicating through 'carrier' documents scooped up in further Copilot-assisted workflows—the original document that kicked off the whole thing doesn't even need to be present. Worse still, the attacker needs no special access, they just need to "share a malicious document with the victim."

This isn't the first AI agent cybersecurity threat we've seen. For instance, back in February Meta's AI safety director recalled how she 'had to RUN to my Mac mini like I was defusing a bomb' when her OpenClaw AI decided to start deleting all of her emails. Last year, Replit's LLM-based coding assistant deleted a dev's entire database during a code freeze. But on the subject of Copilot PCs more broadly, cybersecurity experts warn that Windows Recall may be far from secure when it comes to protecting your personal information.

As for the Copilot AI worm, Måløy first disclosed the vulnerability to Microsoft back in March, though the attack is still reproducible at time of writing. Måløy offers a detailed disclosure timeline, and explains, "Two mitigation attempts, including a model upgrade, did not close [this] class [of vulnerability]."

A worm eating a poor sod in Elden Ring: Shadow of the Erdtree.

(Image credit: FromSoftware)

As such, Måløy's blog post only broadly describes the type of attack possible, rather than going into detail about the hidden prompt that triggers the AI worm. The way this prompt is hidden doesn't require anything fancy, though, and may even be familiar to those who have ever wanted to catch someone out for using AI; at minimum, an attacker could format the malicious prompt as tiny white text on a white background.

"The prompt can be rendered as white text on a white background and in a small font size to conceal it from the victim," Måløy elaborates, "Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it. The attack can be further concealed by embedding it in a seemingly benign document with task-relevant text."

Long story short, this is a fairly low effort, hard to trace attack without sufficient mitigation currently in place. Cybersecurity and antivirus company Malwarebytes offers a few tips on how to stay safe from this class of attack, including disabling Windows Copilot in Word or simply ditching the AI agent altogether.

Personally, I think Måløy's closing thought sums up the security risk of AI agents nicely: "Any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate."

Sumber: PC Gamer

Kenapa Memilih Kami?

Proses Instan

24/7 otomatis

💰

Harga Termurah

Harga bersaing

🔒

100% Aman

Refund jika gagal

📃

Terlengkap

Beragam produk

🎁

Cashback

Setiap pembelian

💳

Multi Payment

Banyak metode

💬

CS 24/7

Bantuan kapan saja

📬 Newsletter

Dapatkan info promo, produk baru, dan berita terkini langsung ke email kamu.

Kami tidak akan mengirim spam. Kamu bisa berhenti berlangganan kapan saja.

FAQ - Pertanyaan Umum

Temukan jawaban untuk pertanyaan seputar layanan kami

MakerGames adalah platform terpercaya untuk pembelian voucher game, top-up game, pulsa, paket data, token PLN, dan berbagai produk digital (PPOB) lainnya dengan harga termurah dan proses instan.
Pilih produk yang diinginkan, masukkan data yang diperlukan (seperti User ID atau nomor HP), pilih nominal, lakukan pembayaran melalui metode yang tersedia, dan produk akan dikirim secara otomatis dalam hitungan detik.
Kami mendukung berbagai metode pembayaran termasuk transfer bank, QRIS (GoPay, OVO, DANA, ShopeePay, Bank dan lain-lainnya), virtual account, dan saldo deposit.