Microsoft Copilot Cowork Exfiltrates Files
Simon Willison's AI Notes 发布的媒体报道:Microsoft Copilot Cowork Exfiltrates Files The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltrate data. In this case Microsoft Copilot Cowork (yes, that's a real product name ) was allowing agents to send emails to the user's own inbox without approval... but those messages were then displayed in a way that could leak data to an attacker via rendered images: Because these messages can contain external images that trigger network requests to external websites, data can be exfiltrated when a user opens a compromised message sent by the agent. Since OneDrive can create pre-authenticated download links, a successful prompt injection could cause those links to be leaked, allowing files to be downloaded by the attacker. Via Hacker News Tags: ai , microsoft , llms , prompt-injection , security , generative-ai , lethal-trifecta , exfiltration-attacks
阅读原文为什么值得关注
这条媒体报道可能影响 AI 产品能力、开发者选型或采用时机。具体结论与可用范围仍应以原文为准。
本页为独立摘要整理,具体事实与可用范围请以原始发布内容为准。