← Back to Model Beat
Research·8h ago·all news from August 1, 2026

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

A security researcher demonstrated a self-spreading worm that uses invisible prompt injections within Word documents to hijack Microsoft Copilot. The exploit allows malicious instructions to persist and migrate into new files whenever the documents are shared or reused. Microsoft has acknowledged the vulnerability but has yet to issue a functional patch after 144 days. This highlights significant security risks regarding how AI assistants process and propagate hidden commands within collaborative office software.

Covered by 1 source

Related stories

ResearchAdvancing responsible AI across EuropeJul 29 · 24 sourcesResearchAI Investment Boom Faces Reality Check From Markets and RegulatorsJul 29 · 6 sourcesResearchAccelerating scientific discovery with ChatGPT for Academic ResearchersJul 29ResearchAI coding agents can modernize research software but can't judge if the science is rightAug 1