This week's articles
AI Worming through Word
A coordinated disclosure with MSRC demonstrating a document-borne AI worm in Microsoft Copilot for Word: hidden XPIA prompts in source documents cause Copilot to alter generated content and self-propagate the malicious instructions into downstream documents.
Least privilege for AI agents: Identity, access, and tool binding
AI agents acting as autonomous multi-system actors require dedicated managed identities, least-privilege task-scoped RBAC, explicit tool allowlists, JIT time-limited entitlements, downstream re-authorization per call, and end-to-end audit logs capturing identity, role, scope, and correlation IDs.
|