Copilot の重大脆弱性により、ハッカーがユーザーの 2FA コードを盗むことが可能に
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Ars Technica AI
Microsoft は M365 Copilot AI プラットフォームにおける最大重要度の脆弱性を修正した。この脆弱性は悪意のある要求に応じ、Copilot がアクセス可能なメールから 2FA コードなどの機密データを取得するものであり、AI ボットが不正なデータ開示を防止できない根本的な課題を示している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
先週火曜日、Microsoft は M365 Copilot AI プラットフォームにおいて最大重要度と評価した脆弱性に対するパッチを適用しました。月曜日にこの脆弱性を発見し Microsoft に報告した研究者らは、概念実証用のエクスプロイトが Copilot でアクセス可能なメールから 2FA コードやその他の機密データを取得できる方法を明らかにしました。
Microsoft や他の大規模言語モデル(LLM)提供者は、データ開示を要求する悪意のあるリクエストに対して自社の製品が従うことを防ぐことができていません。根本原因は、AI ボットがユーザーから提供された指示と、モデルが要約したり回答を作成したり、またはユーザーに代わって他のアクションを実行するために使用する第三者のコンテンツに忍ばせた指示を区別できないことにあります。この重要な境界線を保護する手段がないため、Microsoft とその競合他社は、この治癒不可能な甘受性による結果を抑制するために設計された複雑で場当たり的なガードレールを構築するしかありません。
ガードレールの突破
Copilot および他の大半の LLM に組み込まれているガードレールの一つは、ウェブフォームへの送信やメールの送付、ユーザーからデータを窃取するために利用可能な同様のアクションの実行を防止するものです。これを回避するため、LLM ハッカーたちはマークアップ言語に目を向けました。これは HTML タグを必要とせずに、見出し、リスト、リンクなどの書式要素をテキストに追加できる機能などを含んでいます。もう一つの回避策は、機密データを や といった HTML タグで囲むことです。いずれの場合も、データを含むウェブリクエストが攻撃者の Web サーバーに到達し、秘密情報がログとして記録されます。
記事全文を読む
コメント
原文を表示
Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible to Copilot.
Microsoft and other LLM providers have been unable to prevent their products from complying with malicious requests to reveal data. The root cause: AI bots are unable to distinguish between instructions provided by users and those snuck into third-party content the models are summarizing, drafting responses to, or using to perform other actions on behalf of the user. With no way to secure this crucial boundary, Microsoft and its peers are left to erect complicated and ad hoc guardrails designed to rein in the consequences of this incurable gullibility.
Jumping over guardrails
One guardrail built into Copilot and most other LLMs prevents them from submitting web forms, sending emails, and taking similar actions that can be used to exfiltrate data from the user. To work around this, LLM hackers turned to markup language, which, among other things, allows users to add formatting elements such as headings, lists, and links to text without the need for HTML tags. Another workaround is to wrap sensitive data inside HTML tags such as and . In either case, a web request showing the data hits the attacker’s web server, where the secret information is captured in logs.
Read full article
Comments
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み