Log in Download Integrations Articles News Pricing FAQ Contact
Русский Қазақша 中文
An AI assistant hacked via hidden input: a security lesson for every AI adopter

Ars Technica · August 18, 2026 · 1Cifer

An AI assistant hacked via hidden input: a security lesson for every AI adopter

Security researchers disclosed details of how Copilot, the AI assistant in Microsoft's office suite, was hacked: attackers steered it through hidden input — instructions concealed in content the assistant reads but the user never sees. The model executed someone else's commands, taking them for part of its task.

This is textbook prompt injection — a fundamental vulnerability of all large language models, not one product's defect. Any AI assistant that reads incoming mail, documents from external sources or web pages can encounter hidden instructions in them: white text on a white background, metadata, invisible blocks. The more rights an assistant holds — reading correspondence, sending emails, taking actions — the more a successful injection costs.

For companies deploying AI, three rules follow. Grant assistants the minimum necessary rights — like a new hire on probation, not an administrator. Require human confirmation for irreversible actions: moving money, sending letters, deleting data. And choose platforms where access boundaries are set explicitly — by role and position, not "everything for everyone". AI agents pay off exactly when their powers are drawn as soberly as people's.

Related stories

Suspecting the court of using AI, a litigant hid prompts in his case filingsDefenders are now embracing prompt injection: AI agents' biggest weakness becomes a defensive weaponAn OpenAI model posted internal company data to public GitHub — a lesson for anyone granting AI access

Reading us regularly? Add 1Cifer to your preferred sources in Google — our stories will show up in your news feed more often.

Add in Google

All news →