Today in "we're not ready":
“any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate”
https://bit.ly/4x7dPiW

bit.ly
Word worm crawls into Copilot, spreads chaos
Researcher says months of coordination with Microsoft have yet to produce a robust mitigation