Word worm crawls into Copilot, spreads chaos
Håkon Møløy said Microsoft’s fixes have not closed the flaw after 144 days, and a malicious Word file can still spread through Copilot workflows.
- 144 days after a researcher warned Microsoft, a document-borne AI-worm still functions, allowing attackers to manipulate Copilot by embedding hidden text within Word documents.
- Copilot treats document content as prompts, creating a vulnerability where hidden instructions manipulate output; asking a model to evaluate untrusted code just leads to "LLMs all the way down."
- Microsoft attempted to mitigate the issue by blocking specific prompts and upgrading to GPT-5, but attackers simply reworded the payload, rendering both fixes ineffective.
- Pointing to a defense-in-depth strategy blocking malicious instructions "at multiple points," the company acknowledged that "prompting alone is not a reliable security boundary."
- Satya Nadella confirmed a Copilot "super app" launching this year with revenue up 60%, while SecurityWeek reported similar "hallusquatting" risks from Tel Aviv University and Intuit researchers.
15 Articles
15 Articles
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word documents, for example, as input to a financial repor…
In the world of advanced technology, security vulnerabilities stand out as serious threats. In this article, we examine a new vulnerability in Microsoft Copilot for Word, where hidden instructions can compromise document integrity. The leakage of hidden instructions in Word documents by Microsoft Copilot can cause the hidden instructions in a Microsoft 365 Word document to rewrite numbers in a report and then copy the same instructions to the fi…
Word worm crawls into Copilot, spreads chaos
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog …
A security researcher has demonstrated that a Word trapped document can contaminate all the files generated by Copilot, and spread from document to document, without intervention by the attacker. 144 days of coordination with Microsoft, two attempts to fix, an upgrade to the underlying IA model. And
Hidden Prompt Can Make Microsoft Copilot Spread Through Word Docs: What Businesses Should Know
A hidden prompt injection technique can turn Microsoft Copilot Word documents into carriers for malicious instructions, creating new security risks for enterprises using AI assistants
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











