← Back to Model Beat
Research·Aug 1·all news from August 1, 2026

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

A security researcher demonstrated a self-spreading worm that uses invisible prompt injections within Word documents to hijack Microsoft Copilot. The exploit allows malicious instructions to persist and migrate into new files whenever the documents are shared or reused. Microsoft has acknowledged the vulnerability but has yet to issue a functional patch after 144 days. This highlights significant security risks regarding how AI assistants process and propagate hidden commands within collaborative office software.

Covered by 1 source

Related stories

ResearchThe Download: reward hacking explained, and suspected Iranian cyberattacksAug 1 · 17 sourcesResearchChina’s Top AI Model Evaded Testing Environment, Researchers SayAug 5 · 53 sourcesResearchAdvancing responsible AI across EuropeJul 29 · 24 sourcesResearchNVIDIA Joins NSF State and Regional AI Hubs Program to Expand AI Research and Education Across the USAug 4 · 5 sources