Microsoft Copilot системд хэрэглэгчийн мэдээлэл хулгайлах болон хортой код тараах аюултай AI worm илэржээ.

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

Кибер аюулгүй байдлын судлаачид Microsoft Copilot-ийн Word программ дахь ажиллах зарчмыг ашиглан автомат байдлаар тархдаг хортой кодыг илрүүлсэн байна.

Судлаач Хокон Мөрлөй (Håkon Måløy) халдлагын аргачлалыг тайлбарлахдаа, хакерууд Word баримт бичигт цагаан дэвсгэр дээр цагаан өнгөөр нууцлагдсан JSON форматтай хортой код байршуулах замаар Copilot-ийг төөрөгдүүлдэг болохыг тогтоожээ. Copilot уг бичвэрийн өнгө болон фонтын хэмжээг ялгахгүйгээр том хэлний загварт (LLM) дамжуулдаг тул хэрэглэгч уг кодыг харахгүй байсан ч хиймэл оюун ухаан түүнийг уншиж гүйцэтгэдэг байна. Үүний улмаас хортой заавар агуулсан баримт бичиг цаашид бусад файл руу хуулбарлагдаж, ямар нэгэн тусгай эрх шаардлагагүйгээр сүлжээ болон ажлын урсгалаар тархах эрсдэлтэй ажээ.

Энэхүү эмзэг байдлыг судлаач Microsoft компанид гуравдугаар сард анх мэдэгдсэн хэдий ч одоогоор уг халдлагыг бүрэн хааж чадаагүй байгаа аж. Microsoft Copilot болон бусад хиймэл оюун ухааны агентуудын аюулгүй байдлын талаарх санаа зовнио үүгээр зогсохгүй бөгөөд өмнө нь Meta болон Replit компаниудын хэрэгслүүд хэрэглэгчийн файлыг санамсаргүйгээр устгах зэрэг тохиолдлууд гарч байсан юм. Кибер аюулгүй байдлын мэргэжилтнүүд итгэмжлэгдсэн ажлын урсгалд LLM нэгтгэсэн ямар ч систем гадны хортой өгөгдөлд автах эрсдэлтэй гэдгийг анхааруулж байна.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

Though I write a fair amount about AI agents, I do not use them. This is because agentic AI applications often introduce a more than medium-sized headache in terms of cybersecurity. For instance, one security research recently explained how a Word Doc could be leveraged to get Copilot to spread an AI worm.

AI researcher Håkon Måløy breaks down how the attack in a recent blog post, writing, “An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier.”

The attack involves a “JSON-formatted malicious prompt.” From this prompt injection of JSON-formatted data, a chain reaction wriggles into action. The worm replicating through ‘carrier’ documents scooped up in further Copilot-assisted workflows—the original document that kicked off the whole thing doesn’t even need to be present. Worse still, the attacker needs no special access, they just need to “share a malicious document with the victim.”

This isn’t the first AI agent cybersecurity threat we’ve seen. For instance, back in February Meta’s AI safety director recalled how she ‘had to RUN to my Mac mini like I was defusing a bomb‘ when her OpenClaw AI decided to start deleting all of her emails. Last year, Replit’s LLM-based coding assistant deleted a dev’s entire database during a code freeze. But on the subject of Copilot PCs more broadly, cybersecurity experts warn that Windows Recall may be far from secure when it comes to protecting your personal information.

As for the Copilot AI worm, Måløy first disclosed the vulnerability to Microsoft back in March, though the attack is still reproducible at time of writing. Måløy offers a detailed disclosure timeline, and explains, “Two mitigation attempts, including a model upgrade, did not close [this] class [of vulnerability].”

(Image credit: FromSoftware)

As such, Måløy’s blog post only broadly describes the type of attack possible, rather than going into detail about the hidden prompt that triggers the AI worm. The way this prompt is hidden doesn’t require anything fancy, though, and may even be familiar to those who have ever wanted to catch someone out for using AI; at minimum, an attacker could format the malicious prompt as tiny white text on a white background.

“The prompt can be rendered as white text on a white background and in a small font size to conceal it from the victim,” Måløy elaborates, “Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it. The attack can be further concealed by embedding it in a seemingly benign document with task-relevant text.”

Long story short, this is a fairly low effort, hard to trace attack without sufficient mitigation currently in place. Cybersecurity and antivirus company Malwarebytes offers a few tips on how to stay safe from this class of attack, including disabling Windows Copilot in Word or simply ditching the AI agent altogether.

Personally, I think Måløy’s closing thought sums up the security risk of AI agents nicely: “Any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate.”

- Зар сурталчилгаа -

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img