Microsoft Copilot Cowork存在安全漏洞,攻击者可通过提示注入导致数据外泄。该产品允许代理自动发送邮件到用户收件箱,邮件中的外部图片可触发网络请求泄露数据。同时,OneDrive生成的预认证下载链接可能被利用,使攻击者下载文件。
Microsoft Copilot Cowork Exfiltrates Files
The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltrate data.
In this case Microsoft Copilot Cowork (yes, that's a real product name) was allowing agents to send emails to the user's own inbox without approval... but those messages were then displayed in a way that could leak data to an attacker via rendered images:
Because these messages can contain external images that trigger network requests to external websites, data can be exfiltrated when a user opens a compromised message sent by the agent.
Since OneDrive can create pre-authenticated download links, a successful prompt injection could cause those links to be leaked, allowing files to be downloaded by the attacker.
Via Hacker News
Tags: microsoft, security, ai, prompt-injection, generative-ai, llms, exfiltration-attacks, lethal-trifecta