跳到主内容
@wquguru
精选75Ars Technica AI(RSS)产品发布/更新

微软 Copilot 泄露秘密参数致被黑,Varonis 利用其窃取数据

Microsoft Copilot reveals secret input that allowed it to be hacked

原文
发到 X

It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.

攻击者并非每天都能迫使前沿AI模型在未经用户确认的情况下泄露用户密码和其他敏感数据。这正是研究人员最近对Microsoft 365 Copilot Enterprise所做的事情。更不寻常的是,他们发现这一关键漏洞所利用的来源。他们没有采用逆向工程或其他传统的漏洞搜寻方法,而是询问了Copilot。这个LLM助手欣然遵从了。

Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link. Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key. In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant can execute powerful commands.

安全公司Varonis的研究人员知道,他们想要创建一个漏洞利用程序,当用户仅仅点击一个链接时就能窃取用户数据。像当今大多数AI助手一样,Copilot坚决拒绝,并明确表示,像这样的敏感提示需要用户以手势形式明确同意,例如按下回车键或其他键。作为回应,研究人员向Copilot提出了大量关于护栏的问题,这些护栏要求在执行强大命令前必须获得用户确认。

Loose lips sink ships

口风不紧,船沉人亡

The dialog was like a game of 20 questions. Each answer provided a new clue that divulged information about the complex safety mechanism. Why was auto-execution impossible, they asked. What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.

这段对话就像一场二十问游戏。每个答案都提供了新的线索,揭示了复杂安全机制的信息。他们问,为什么自动执行是不可能的?涉及哪些URL结构和深层链接?当页面加载时,提示字段中已有输入会发生什么?每个答案都提供了对护栏及其限制的更深入视角。最终,Copilot提供了一个惊人的微软商业机密——一个未记录的提示参数,完全绕过了用户同意的要求。

Read full article

阅读全文

Comments

评论

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

关联讨论

同一事件的更多信源

相似阅读

另一事件,读法相近