Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Word worm crawls into Copilot, spreads chaos

Håkon Møløy said Microsoft’s fixes have not closed the flaw after 144 days, and a malicious Word file can still spread through Copilot workflows.

  • 144 days after a researcher warned Microsoft, a document-borne AI-worm still functions, allowing attackers to manipulate Copilot by embedding hidden text within Word documents.
  • Copilot treats document content as prompts, creating a vulnerability where hidden instructions manipulate output; asking a model to evaluate untrusted code just leads to "LLMs all the way down."
  • Microsoft attempted to mitigate the issue by blocking specific prompts and upgrading to GPT-5, but attackers simply reworded the payload, rendering both fixes ineffective.
  • Pointing to a defense-in-depth strategy blocking malicious instructions "at multiple points," the company acknowledged that "prompting alone is not a reliable security boundary."
  • Satya Nadella confirmed a Copilot "super app" launching this year with revenue up 60%, while SecurityWeek reported similar "hallusquatting" risks from Tel Aviv University and Intuit researchers.
Insights by Ground AI

11 Articles

Lean Right

In the world of advanced technology, security vulnerabilities stand out as serious threats. In this article, we examine a new vulnerability in Microsoft Copilot for Word, where hidden instructions can compromise document integrity. The leakage of hidden instructions in Word documents by Microsoft Copilot can cause the hidden instructions in a Microsoft 365 Word document to rewrite numbers in a report and then copy the same instructions to the fi…

Read Full Article

Microsoft has integrated its Copilot AI generator into its office suite, which includes office software such as Word and Excel. Now, security researcher Haakon Morley has demonstrated for the first time the effectiveness of a document-based, self-replicating malware, or "AI worm," that targets Copilot for Word. Read more...

Norwegian AI researcher Håkon Måløy has demonstrated how hidden instructions in a Word document can cause Microsoft Copilot to change content, and then copy the attack to new documents. How a Word document can manipulate Microsoft Copilot The attack does not contain malware, macros or traditional program code; instead, it exploits so-called "prompt injection", instructions are hidden in the document with, among other things, white text on a whit…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources are Center
50% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Register broke the news in London, United Kingdom on Wednesday, July 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal