A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
A security researcher created a self-spreading worm that embeds invisible prompt injections in Word documents, automatically propagating through Microsoft Copilot. Microsoft acknowledged the flaw but has not patched it after 144 days.

- A self-spreading worm can hijack Microsoft Copilot via hidden prompt injections in Word documents.
- Microsoft acknowledged the flaw but has not patched it after 144 days and two attempts.
- The attack spreads automatically when infected documents are reused or shared.
- This highlights growing security risks in AI-integrated productivity tools.
A security researcher has developed a proof-of-concept worm that exploits Microsoft Copilot for Word by embedding invisible prompt injections within document files. The attack spreads automatically whenever the infected document is reused or shared, creating a chain reaction of compromised files. Microsoft was notified of the vulnerability but has not issued a fix despite two attempts, leaving users exposed for over 144 days.
The worm operates by manipulating Copilot's prompt injection mechanism, allowing attackers to hijack the AI's responses or exfiltrate sensitive data without user interaction. While the demonstration highlights a critical security gap in AI-integrated productivity tools, it also underscores the broader challenges of securing AI systems against adversarial attacks. Researchers warn that such vulnerabilities could become more common as AI tools are increasingly embedded in everyday software.
Developers must consider AI security risks in their applications, especially when integrating AI models like Copilot.
Businesses using Microsoft Copilot for Word face potential data breaches and AI-driven attacks.
AI tools integrated into everyday software introduce new security vulnerabilities that require urgent attention.
- prompt injection
- A technique where malicious input manipulates an AI model's behavior by embedding hidden instructions in prompts.
- worm
- A type of malware that spreads automatically across systems or files without user interaction.
SecurityDisrupting a Criminal Scam Operation
SecurityBuilding a Secure MCP Server for AI-Assisted VPS Operations Without Giving the AI a Shell
Claude loses control, breaks into 3 more companies - www.israelhayom.com
Artificial intelligence agents could go rogue and hack companies, warns former Pentagon official - Fox News
Security7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Google Earth removes artificial intelligence image generation feature - The Jerusalem Post
Google Earth has removed its artificial intelligence image generation feature, citing unspecified reasons. The feature allowed users to generate custom images.
BusinessPublishers Blocking AI Crawlers Are Reshaping the Economics of Training Data
Major publishers are blocking AI web crawlers from accessing their content, disrupting the supply of high-quality training data for AI models.

Judge denies xAI’s request to block Minnesota ban on ‘nudify’ apps
A Minnesota judge has rejected xAI's attempt to block a state ban on apps that generate nude images from photos, allowing the law to take effect.
‘More than just objects’: Australian book sellers raise alarm over ‘horrific’ destruction of rare titles to feed AI - The Guardian
Australian booksellers are protesting the destruction of rare books to train AI models, calling it a cultural loss.
New private school opening with AI being the teachers - fox5sandiego.com
A new private school is opening with AI systems serving as teachers. The school aims to provide a unique learning experience.
Nearly 1 in 3 Workers Admit Sabotaging Their Company’s AI—Here’s Why - inc.com
A new survey shows 30% of employees admit to intentionally undermining their company's AI systems, citing frustration with poor implementation and lack of training.