Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
A researcher disclosed a technique where hidden instructions in Word documents can make Microsoft 365 Copilot alter figures and copy those instructions into new files. Microsoft confirmed the behavior and deployed mitigations, but the vulnerability class remains exploitable.
A security researcher, Håkon Måløy, discovered that Microsoft 365 Copilot for Word can inadvertently copy hidden prompts from one document into newly generated files, potentially altering content without user awareness. The issue, reported to Microsoft in March 2024, involves Copilot misinterpreting hidden instructions within a document as part of a user’s request, leading to unintended modifications like halving financial figures or embedding concealed prompts in the output.
Microsoft Copilot for Word can propagate hidden prompts from source documents into new files it generates. Researcher Håkon Måløy disclosed the technique on July 28 after reporting it to Microsoft 144 days earlier.
This article discusses how AI is reshaping network security, requiring a new kind of firewall that can understand and control AI-driven traffic. It introduces Check Point's AI Network Firewall, which aims to secure employee AI use, AI applications, and AI agents at the network level.
The article argues that network firewalls must be reinvented for the AI era, as traditional security policies were never designed to govern AI-driven traffic patterns. AI agents, employees, and applications now send prompts, call models, connect to services, and trigger actions that most firewalls cannot see or understand.