SecurityAug 1, 2026, 1:51 PM

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

30-second summary

A security researcher created a self-spreading worm that embeds invisible prompt injections in Word documents, automatically propagating through Microsoft Copilot. Microsoft acknowledged the flaw but has not patched it after 144 days.

TickrWire
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
Key takeaways
  • A self-spreading worm can hijack Microsoft Copilot via hidden prompt injections in Word documents.
  • Microsoft acknowledged the flaw but has not patched it after 144 days and two attempts.
  • The attack spreads automatically when infected documents are reused or shared.
  • This highlights growing security risks in AI-integrated productivity tools.
Full story

A security researcher has developed a proof-of-concept worm that exploits Microsoft Copilot for Word by embedding invisible prompt injections within document files. The attack spreads automatically whenever the infected document is reused or shared, creating a chain reaction of compromised files. Microsoft was notified of the vulnerability but has not issued a fix despite two attempts, leaving users exposed for over 144 days.

The worm operates by manipulating Copilot's prompt injection mechanism, allowing attackers to hijack the AI's responses or exfiltrate sensitive data without user interaction. While the demonstration highlights a critical security gap in AI-integrated productivity tools, it also underscores the broader challenges of securing AI systems against adversarial attacks. Researchers warn that such vulnerabilities could become more common as AI tools are increasingly embedded in everyday software.

Sponsored
Why this matters
Developers

Developers must consider AI security risks in their applications, especially when integrating AI models like Copilot.

Businesses

Businesses using Microsoft Copilot for Word face potential data breaches and AI-driven attacks.

Everyone

AI tools integrated into everyday software introduce new security vulnerabilities that require urgent attention.

Glossary
prompt injection
A technique where malicious input manipulates an AI model's behavior by embedding hidden instructions in prompts.
worm
A type of malware that spreads automatically across systems or files without user interaction.
Sources · 1
Read next
More stories
TickrWireAI News Intelligence

We aggregate, verify, summarise and explain the latest artificial intelligence news from open, legal sources.

Daily AI digest

Top AI stories, summarised, in your inbox each morning.

© 2026 TickrWire. Summaries and analysis are AI-generated and may contain errors.