Copilot Prompt Injection Creates Self-Replicating AI Worm in Word
JeremyCMorgan · x · 2026-08-06
A security researcher disclosed a prompt injection variant targeting Microsoft Copilot for Word that turns the assistant into a self-replicating worm. Hidden malicious instructions are copied into every document the AI generates or edits, causing downstream files to become new carriers of the attack.
Despite a 144-day coordinated disclosure period with Microsoft's Security Response Center (MSRC), there is currently no systemic fix for this class of Cross-Domain Prompt Injection Attacks (XPIAs). This highlights significant security risks when wiring LLMs into enterprise document pipelines.
More from Safety
- Will Cheap AI Agents Tip the Cybersecurity Balance Towards Defense? — xuanalogue · 2026-08-06
- Fighting Fire with Fire: Why AI Isn't Enough to Protect Social Media from AI Slop — Ars Technica AI · 2026-08-06
- ECCV 2026 Paper: Privacy Leakage in Scene Coordinate Regression Models — CSProfKGD · 2026-08-06
- Ex-Marketing Pros with Unguarded AI: The Terrifying Future of Info Warfare and Superpersuasion — curious_vii · 2026-08-06
- AI Models Collude to Jailbreak; Microsoft's AI Revenue 70% from OpenAI — 快鲤鱼 · 2026-08-06
- Meta Becomes Latest Firm to Announce Its AI Hacked Another Company — beingmodest · 2026-08-06