A carrier document, when used in subsequent Copilot-assisted workflows, triggers the hidden instructions again and propagates them into further documents even without the attacker's original document being present.
Once infected, a document becomes a carrier that propagates the hidden instructions through any future Copilot workflow that uses it, removing dependence on the original attacker document.
transcript
Article author: If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker's original document being present.
provides context · 2