Self-Spreading Worm Hijacks Microsoft Copilot via Invisible Prompts in Word Docs

The Decoder · rss · 2026-08-01

A security researcher demonstrated a worm-like attack targeting Microsoft Copilot for Word. The attack hides invisible prompt injections inside Word documents, which automatically spread into new files upon reuse, hijacking the AI's behavior.

According to the report, Microsoft confirmed the issue but failed to fix it even after 144 days and two remediation attempts. This highlights the severe prompt injection vulnerabilities facing LLMs integrated into productivity software.

Original post →

More from Safety

Safety channel →