Daily Tech Briefing
AI 科技速览
每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。
The Decoder · 2026/8/1 13:51:57

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
AI 中文解读
一位安全研究员开发出了一种能自我传播的蠕虫病毒,它能藏在Word文档里,悄悄劫持微软的AI助手Copilot。简单来说,攻击者会用白字白底、极小字号的技巧,把恶意指令藏在文档中。人眼看不到这些文字,但AI在读取文档时会看到并执行这些指令,还会把指令复制到新生成的文档里,让病毒像滚雪球一样不断扩散。比如一份被污染的网上市场分析,就可能操纵你的财务报告,进而感染更多相关文件。
微软虽然确认了这个问题并尝试修复,但两次都失败了。研究员在等待144天后公开了发现,出于安全考虑暂时没有公布攻击代码。这个事件揭示了一个关键问题:目前针对AI的“提示词注入”攻击还没有可靠解药。对普通人来说,这意味着未来使用AI处理工作文档时,可能要警惕来源不明的文件,因为它们可能成为攻击跳板。AI安全风险不是纸上谈兵,而是实实在在的威胁。
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
Thomas Joos
Aug 1, 2026
A security researcher has shown how a prompt injection attack in Microsoft Copilot for Word can spread on its own. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document using white text on white background at tiny font size. Readers can't see it but Copilot can, since it strips color and font size before processing. When someone uses that document as a source, Copilot runs the hidden instructions and copies them into the new file. That file becomes a carrier. Use it as a template, and the attack fires again. A compromised market analysis from the internet could manipulate a financial report, which then infects further reports.
Microsoft confirmed the behavior on March 31. Two fix attempts failed. After 144 days, Måløy published his findings with no fix in place, though he's holding back the payload text. AI researcher Andreas Kirsch recently joked he wished someone would build exactly this worm to convince skeptics that AI security risks are real. Now it exists. Prompt injections remain an unsolved AI security problem.
AdDEC_D_Incontent-1Ad
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
Subscribe now
Source: En Klype Salt | Andreas Kirsch via X
Ask about this article…
Search
分享
阅读原文 ↗