www.malwarebytes.com 7/30/2026, 2:31:43 PM · external

Microsoft Copilot Word flaw lets hidden prompts spread AI worm

Microsoft Copilot Word flaw lets hidden prompts spread AI worm
Developing story vulnerability 3 articles tracked
Microsoft Copilot for Word prompt injection vulnerability enables AI worm spread
CyberSIXT Evidence Panel
Primary Source enklypesalt.com

A security researcher has revealed that Microsoft Copilot for Word can be exploited to spread a self-propagating "AI worm" through hidden prompt injections in documents. The attack enables a malicious JSON prompt to be embedded as white text in Word files. When Copilot processes these documents, it reads the hidden instructions and modifies them accordingly, creating a chain reaction that propagates further documents through legitimate user actions.

Currently, there's no full mitigation for this type of attack in large language models like Copilot. Users are advised to treat external documents as untrusted, review them before use, and disable Copilot if necessary to reduce risk.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline