"The initial attack vector for these scenarios uses a malicious document. The malicious document contains a JSON-formatted malicious prompt that triggers the attack when the document is included in Copilot’s context. The prompt can be rendered as white text on a white background and in a small font size to conceal it from the victim. Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it.”

This is so silly. I can’t believe it worked until very recently (and probably still works, except not exactly in this way).

you are viewing a single comment's thread
view the rest of the comments
[–] 25 points 1 month ago* (1 child)
  • [–] 8 points 1 month ago* (1 child)

    She be fucken rollin in fridge magnets and quirky collectibles.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 1 month ago (1 child)

    I just want to acknowledge that my comment is sandwiched between schmorpel and schipelblorp.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 1 month ago (1 child)

    Lemmy is a smorgasbord for user names.

  • source
  • parent
  • hideshow 2 child comments