AI news story
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it
Editor's take
A security researcher has successfully demonstrated a stealthy worm capable of infecting Microsoft Word documents and propagating itself through its integration with Microsoft Copilot. This exploit leverages invisible prompt injections within documents, which then automatically spread to any new files created or edited using those infected documents, effectively hijacking Copilot's functionality.
This development is significant because it highlights a novel attack vector targeting the increasingly integrated AI assistants within productivity software. The implications extend beyond individual users to enterprise environments where sensitive data is processed, potentially leading to widespread data exfiltration or manipulation. It underscores the security challenges inherent in embedding powerful AI models into everyday workflows, especially when those models interpret user-provided content.
Future attention should focus on Microsoft's response and the broader industry's ability to secure AI-powered applications. Specifically, observing whether Microsoft implements robust sanitization for document content that interacts with Copilot, and how other AI vendors address similar vulnerabilities in their integrated tools, will be critical. The effectiveness of future defenses against such prompt injection attacks will determine the security posture of AI-assisted productivity.
Signal score: 3
This event was corroborated by 23 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.
Original reporting
This story summarises reporting published by The Decoder. Read the original article at The Decoder.