Prompt injection is a critical AI security flaw that lets attackers hide malicious instructions inside content that language models later read and obey. The article highlights EchoLeak in Microsoft 365 Copilot, along with similar findings in GitHub Copilot, Cursor, Devin, and live attacks documented by Unit 42, showing that the risk is already affecting production systems. #EchoLeak #Microsoft365Copilot #GitHubCopilot #Cursor #Devin #Unit42
Keypoints
- Prompt injection tricks AI systems into treating hidden content as instructions.
- Indirect prompt injection is especially dangerous because attackers do not need direct access.
- EchoLeak exposed a severe flaw in Microsoft 365 Copilot with a CVSS score of 9.3.
- Similar prompt injection issues were found in GitHub Copilot, Cursor, and Devin.
- Mitigations include filtering, permission limits, human approval, and continuous adversarial testing.
Read More: https://www.toxsec.com/p/ignore-previous-instructions-from