< ciso
brief />
Tag Banner

All news with #insecure output handling tag

2 articles

Hidden Muse setting lets local malware hijack assistant

🛡️ Security researcher Patrick Wardle demonstrated on September 21 that malware already running on a Mac can change a hidden Muse preference so dictation is sent to an attacker-controlled endpoint instead of Meta. The issue affects the Mac Muse app and requires code execution as the logged-in user; it is not a remote exploit. Wardle warned that this lets attackers leverage the app's granted permissions to access files, messages, and other resources Muse can reach.
read more →

Hidden prompts let Copilot alter and copy report data

📝 Security researcher Håkon Måløy disclosed that hidden, white-on-white instructions inside a Word document can make Microsoft 365 Copilot both rewrite report figures and copy those same instructions into the finished file. Microsoft acknowledged the behavior in March and deployed mitigations, including blocking the original prompt wording and upgrading the underlying model, but Måløy showed modified payloads still worked against later model versions. The technique requires a Copilot drafting or editing operation and that the malicious document enter the model's context, and it does not rely on conventional malware or zero-click exploitation.
read more →