A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
A security researcher demonstrated a self-spreading worm that uses invisible prompt injections within Word documents to hijack Microsoft Copilot. The exploit allows malicious instructions to persist and migrate into new files whenever the documents are shared or reused. Microsoft has acknowledged the vulnerability but has yet to issue a functional patch after 144 days. This highlights significant security risks regarding how AI assistants process and propagate hidden commands within collaborative office software.
Covered by 1 source
- TThe Decoder↗Thomas Joos8h ago