Attackers are increasingly exploiting generative AI by embedding malicious prompts in macros and revealing hidden data through prompt injection. The shift in hacker tactics — as noted in a recent State of File Security study from OPSWAT — requires enterprises to extend the same type of protection they already apply to software production lines and AI environments, according to AI security experts interviewed by CSO.
See also: GhostRedirector hackers compromise Windows Servers with malicious IIS Module

Dane Sherrets, innovation architect at bug bounty platform HackerOne, said that embedding malicious prompts in macros is a prime example of how the capabilities of generative AI can be turned against the systems themselves.
Isolated examples of exploits and malware that abuse generative AI have only begun to emerge this year. For example, researchers at Aim Security recently discovered EchoLeak (CVE-2025-32711) , a zero-click vulnerability discovered in Microsoft 365 Copilot and described as the first such attack on an AI agent. In response to the vulnerability, Microsoft recommended applying patches, restricting access to Copilot, stripping hidden metadata from shared files, and enabling built-in AI security checks.
Another similar attack, CurXecute (CVE-2025-54135), allowed remote code execution via prompt injection in software development environments. “Attackers will continue to find new ways to embed their prompt injections in places that are not visible to the user but are processed by the LLM nonetheless,” said Itay Ravia, lead researcher at Aim Labs.
The “ Skynet ” malware , discovered in June 2025, involved a prompt injection attempt against AI-based security tools. The technique was designed to manipulate AI malware analysis systems into falsely reporting that no malware was detected in a sample through a form of “ Jedi mind trick .” Researchers at Check Point believe the malware was likely a proof-of-concept experiment by malware developers.
See also: GeoServer: Critical vulnerability allows remote code execution

Ensar Seker, CISO at threat intelligence firm SOCRadar, described the abuse of generative AI systems through prompt injection as an evolution in malware delivery tactics. “It’s not just about dropping a payload anymore; it’s about creating dynamic instructions that can manipulate behavior at runtime, and then hiding or encoding those instructions to evade traditional scanning tools,” he said.
Defense against these types of attacks involves a combination of technical defense procedures and policy controls, such as:
- Performing a deep inspection of any file that enters a business environment, especially from untrusted sources.
- Implement policies that isolate macro execution — for example, application sandboxing or Microsoft Protected View.
- Evaluation of content disinfection and reconstruction (CDR) tools.
- Disinfection of any input (prompts) in generative AI systems.
- Implementing protocols to validate AI outputs.
See also: Vulnerabilities fixed in AI Cursor code editor

SOCRadar’s Seker argued that enterprises should treat AI pipelines the same way they handle CI/CD pipelines by extending zero-trust principles to data analytics and AI workflows. In practice, this means introducing guardrails, enforcing output verification, and using contextual filters to block unauthorized instructions from being executed or acted upon by LLM-based systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
