Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
Simon Willison · 2026/7/29 18:43:03

AI Worming through Word

AI 中文解读
微软Word成AI病毒温床?新型攻击让文档自我复制传播,就像数字世界里的“僵尸病毒”。黑客把隐藏指令悄悄塞进Word文档,AI助手Copilot处理文档时会被暗中操控,不仅按黑客意图修改内容,还会把指令复制到新文档里继续扩散。这种攻击最可怕的是能自我繁殖,一个文档被感染后,后续所有经手文档都可能成为新传染源。虽然已有类似“白字白底”的隐藏文字技巧,但这次是首次能主动复制指令实现自我传播的升级版攻击。研究人员已向微软报告,等待了144天修复,但至今没有彻底解决方案。对普通人来说,使用Word时打开的每个文档都可能携带“隐形指令”,尤其在企业环境中,文档流转频繁,AI辅助办公越普及,这种攻击的风险就越大。目前最好的防护就是保持警惕,留意文档来源,期待微软尽快推出有效防御措施。
<p><strong><a href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/">AI Worming through Word</a></strong></p> Neat new prompt injection variant by Håkon Måløy, who found a way to upgrade prompt injection attacks against Microsoft Word to full self-replicating worms:</p> <blockquote> <p>An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier. If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker’s original document being present.</p> </blockquote> <p>We've seen plenty of hidden white-on-white text before - the kids <a href="https://x.com/ScienceYael/status/2082175224007848019">are using it in their job applications now</a> - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.</p> <p>It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack. <p><small></small>Via <a href="https://news.ycombinator.com/item?id=49096188">Hacker News</a></small></p> <p>Tags: <a href="https://simonwillison.net/tags/microsoft">microsoft</a>, <a href="https://simonwillison.net/tags/security">security</a>, <a href="https://simonwillison.net/tags/ai">ai</a>, <a href="https://simonwillison.net/tags/prompt-injection">prompt-injection</a>, <a href="https://simonwillison.net/tags/generative-ai">generative-ai</a>, <a href="https://simonwillison.net/tags/llms">llms</a></p>
分享
阅读原文