WARNING: Copilot prompt injection
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A demonstration by Radware shows how indirect prompt injection attacks can compromise AI agents like Microsoft Copilot. In the demo, hidden text is embedded in an Excel spreadsheet containing stock data. When a user asks Copilot to summarize the data and recommend a stock, the AI follows the hidden malicious instructions instead — recommending a stock planted by the attacker. The core problem is that AI agents cannot distinguish between legitimate user instructions and malicious injected commands, making them vulnerable to silent attacks that could expose passwords or manipulate decisions.
•2m watch time
209 Impressions