frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Microsoft 365 Copilot – Arbitrary Data Exfiltration via Mermaid Diagrams

https://www.adamlogue.com/microsoft-365-copilot-arbitrary-data-exfiltration-via-mermaid-diagrams-fixed/
70•gnabgib•2h ago
https://web.archive.org/web/20251023095538/https://www.adaml...

Comments

simonw•1h ago
That site just gave me a 503 but here's the Internet Archive copy: https://web.archive.org/web/20251023095538/https://www.adaml...

This isn't the first Mermaid prompt injection exfiltration we've seen - here's one from August that was reported by Johann Rehberger against Cursor (and fixed by them): https://embracethered.com/blog/posts/2025/cursor-data-exfilt...

That's mentioned in the linked post. Looks like that attack was different - Cursor's Mermaid implementation could render external images, but Copilot's doesn't let you do that so you need to trick users with a fake Login button that activates a hyperlink instead.

luke-stanley•1h ago
The Lethal Trifecta strikes again! Mermaid seems like a bit of a side issue, presumably there are lots of ways data might leak out. It could have just been a normal link. They should probably look further into the underlying issue: unrelated instruction following.

Thanks for the archive link and the very useful term BTW! I also got 503 when trying to visit.

simonw•1h ago
I think they're doing this the right way. You can't fix unrelated instruction following with current generation LLMs, so given that the only leg you can remove from the trifecta is mechanisms for exfiltrating the data.

The first AI lab to solve unrelated instruction following is going to have SUCH a huge impact.

hshdhdhehd•39m ago
Not even humans can do it perfectly (hence social engineering)
binarymax•1h ago
> MSRC bounty team determined that M365 Copilot was out-of-scope for bounty and therefore not eligible for a reward.

What a shame. There’s probably LOTS of vulns in copilot. This just discourages researchers and responsible disclosure, likely leaving copilot very insecure in the long run.

CaptainOfCoit•1h ago
> There’s probably LOTS of vulns in copilot

Probably exactly why they "determined" it to be out of scope :)

candiddevmike•47m ago
It's irresponsible for any company to be using copilot with MS having this bug bounty attitude, IMO. Would be curious what other products are out of bounds so I know not to use them...
p_ing•45m ago
QQ for the LLM folks -- is this possibly due to the lack of determinization of LLM output?

If I code a var blah = 5*5; I know the answer is always 35. But if I ask an LLM, it seems like the answer could be anything from correct to any incorrect number one could dream up.

We saw this at work with the seahorse emoji question. A variety of [slight] different answers.

nawgz•27m ago
> If I code a var blah = 5*5; I know the answer is always 35

I greatly enjoy the irony here.

anonymars•24m ago
It's okay, we've replaced the Turing test with the em dash test
a-dub•1h ago
" ... BUT most importantly, ... "

i love the use of all capitals for emphasis for important instructions in the malicious prompt. it's almost like an enthusiastic leader of a criminal gang explaining the plot in a dingey diner the night before as the rain pours outside.

Nextgrid•45m ago
It’s both interesting to see all the creative ways people find to exploit LLM-based systems, but also disappointing that to this day designers of these systems don’t want to accept that LLMs are inherently vulnerable to prompt injection and short of significant breakthroughs in AI interpretability will remain hopelessly broken regardless of ad-hoc “mitigations” they implement.
narrator•11m ago
Prompt Injection is an interesting difference between human consciousness and machine "consciousness", or what people try and liken to it. A human can easily tell when information is coming from his memory or internal thoughts and when it is coming from a possibly less reliable outside source. Gaslighting is essentially an attempted prompt injection and is considered psychological abuse. Interestingly, people complain about AI gaslighting them and AI doesn't seem to think that's a problem.

Analysis by Claude of Mt. Gox's 2011 codebase

https://github.com/MagicalTux/mtgox-2011-analysis
1•MagicalTux•1m ago•1 comments

Ask HN: Good LLM Observability Platforms?

1•seany62•5m ago•0 comments

Idea's All Wrong

https://poc-ai.web.app/
1•thefastpoc•9m ago•0 comments

Soho's REI Is Closing–New Yorkers Are Losing Their Favorite Bathroom

https://www.wsj.com/lifestyle/new-yorkers-are-losing-their-favorite-bathroom-rei-bed74dd1
1•walterbell•10m ago•0 comments

Anidap.se – a 100% ad-free anime streaming site

https://anidap.se/home
1•mythril-anvil•10m ago•1 comments

Logitech Muse for Apple Vision Pro

https://www.youtube.com/watch?v=chzOjj0LsD0
1•gdubs•12m ago•0 comments

What our shelves of unread books teach us about ourselves

https://bigthink.com/neuropsych/do-i-own-too-many-books/
1•SanjayMehta•17m ago•0 comments

It's Not Just You – The iOS Keyboard Is Broken [video]

https://www.youtube.com/watch?v=hksVvXONrIo
1•zingerlio•18m ago•1 comments

Crank.js, a JavaScript framework that uses generators for state

https://crank.js.org/
1•jakelazaroff•18m ago•0 comments

Willpower doesn't exist. Why so much of your health isn't your fault

https://www.bbc.com/news/articles/c98nd0d61d0o
3•ggm•20m ago•0 comments

US overdose deaths rising in some regions even as US sees national decline

https://www.theguardian.com/us-news/ng-interactive/2025/oct/17/overdose-deaths-data-analysis
2•gmays•21m ago•0 comments

Chromium is considered an essential nutrient, despite no proven health benefits

https://theconversation.com/why-chromium-is-considered-an-essential-nutrient-despite-having-no-pr...
2•PaulHoule•24m ago•0 comments

Design Twice and Trust in What You Do

https://medium.com/techtrends-digest/design-twice-and-trust-in-what-you-do-e03bb666105f
1•steven86•25m ago•0 comments

Interactive Hiring Pipeline Calculator

https://justoffbyone.com/posts/interactive-hiring-pipeline-calculator/
3•Bogdanp•26m ago•0 comments

9M730 Burevestnik

https://en.wikipedia.org/wiki/9M730_Burevestnik
1•latchkey•28m ago•0 comments

Merge and Conquer: Evolutionarily Optimizing AI for 2048

https://arxiv.org/abs/2510.20205
1•xianshou•28m ago•0 comments

Stuck in the Matrix: Probing Spatial Reasoning in Large Language Models

https://arxiv.org/abs/2510.20198
1•xianshou•29m ago•0 comments

Hyperbolic Non-Euclidean World (2007)

http://web1.kcn.jp/hp28ah77/
1•ubavic•41m ago•0 comments

Putting the "You" in CPU (2023)

https://cpu.land/
2•signa11•41m ago•1 comments

Milei Wins Mandate for Free-Market Revolution in Argentina's Election

https://www.wsj.com/world/americas/milei-wins-mandate-for-free-market-revolution-in-argentinas-el...
5•JumpCrisscross•43m ago•1 comments

Guns n Roses' Appetite for Destruction LP Challenger Disaster Edition

https://www.tomdunnart.com/appetite
2•JumpinJack_Cash•45m ago•0 comments

Oz Labor Gov rules out giving tech giants free rein to mine IPR to train AI

https://www.theguardian.com/technology/2025/oct/27/labor-rules-out-giving-tech-giants-free-rein-t...
2•ggm-at-algebras•55m ago•0 comments

ICE Will Use AI to Surveil Social Media

https://jacobin.com/2025/10/ice-zignal-surveillance-social-media
44•throwaway81523•57m ago•11 comments

China released UBIOS to replace UEFI standard

https://www.tomshardware.com/software/china-releases-ubios-standard-to-replace-uefi-huawei-backed...
4•vincentchau•1h ago•0 comments

Should You Take on Software Modernization Projects?

https://medium.com/@HobokenDays/software-modernization-projects-dilemma-4bd96f3c6502
1•steven86•1h ago•0 comments

Microsoft in court for misleading Australians over Microsoft 365 subscriptions

https://www.accc.gov.au/media-release/microsoft-in-court-for-allegedly-misleading-millions-of-aus...
4•bigfatkitten•1h ago•1 comments

Chaldean Aramaic Words [pdf]

https://aramaicproject.com/StaticFiles/docs/pdf/Chaldean_Language_Course.pdf
2•marysminefnuf•1h ago•0 comments

Using Homebrew to Distribute Early Access Binaries from Private GitHub Reposito

https://lgug2z.com/articles/using-homebrew-to-distribute-early-access-binaries-from-private-githu...
1•todsacerdoti•1h ago•0 comments

Microsoft Accused of Misleading Australians

https://www.smh.com.au/business/consumer-affairs/microsoft-accused-of-misleading-millions-of-aust...
1•femto•1h ago•0 comments

"use php"

https://twitter.com/RicardoSawir/status/1982212646951624748
1•sawirricardo•1h ago•1 comments