AI worm
Coverage of AI worm in the Nexus archive.
- Hidden prompt turns Microsoft Copilot into an AI worm
A security researcher demonstrated how Microsoft Copilot for Word can be exploited via a hidden JSON-formatted prompt embedded in white text on a white background within Word documents. The attack allows the prompt to propagate through document-sharing workflows as Copilot processes the hidden instructions, modifying documents and appending malicious prompts without user awareness. Microsoft's mitigations, including newer GPT models, have not fully resolved the vulnerability, which stems from an architectural weakness in LLM systems.
- U of T researchers demonstrate AI worm could target any online device
University of Toronto researchers have demonstrated an AI worm capable of targeting any online device, highlighting potential security vulnerabilities. The study showcases the ability of AI-driven malware to exploit connected systems without specific device limitations.