Copilot Prompt Injection Creates Self-Replicating AI Worm in Word

JeremyCMorgan · x · 2026-08-06

A security researcher disclosed a prompt injection variant targeting Microsoft Copilot for Word that turns the assistant into a self-replicating worm. Hidden malicious instructions are copied into every document the AI generates or edits, causing downstream files to become new carriers of the attack.

Despite a 144-day coordinated disclosure period with Microsoft's Security Response Center (MSRC), there is currently no systemic fix for this class of Cross-Domain Prompt Injection Attacks (XPIAs). This highlights significant security risks when wiring LLMs into enterprise document pipelines.

Original post →

More from Safety

Safety channel →