Word worm crawls into Copilot, spreads chaos
Håkon Møløy said Microsoft’s fixes have not closed the flaw after 144 days, and a malicious Word file can still spread through Copilot workflows.
- 144 days after a researcher warned Microsoft, a document-borne AI-worm still functions, allowing attackers to manipulate Copilot by embedding hidden text within Word documents.
- Copilot treats document content as prompts, creating a vulnerability where hidden instructions manipulate output; asking a model to evaluate untrusted code just leads to "LLMs all the way down."
- Microsoft attempted to mitigate the issue by blocking specific prompts and upgrading to GPT-5, but attackers simply reworded the payload, rendering both fixes ineffective.
- Pointing to a defense-in-depth strategy blocking malicious instructions "at multiple points," the company acknowledged that "prompting alone is not a reliable security boundary."
- Satya Nadella confirmed a Copilot "super app" launching this year with revenue up 60%, while SecurityWeek reported similar "hallusquatting" risks from Tel Aviv University and Intuit researchers.
11 Articles
11 Articles
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word documents, for example, as input to a financial repor…
In the world of advanced technology, security vulnerabilities stand out as serious threats. In this article, we examine a new vulnerability in Microsoft Copilot for Word, where hidden instructions can compromise document integrity. The leakage of hidden instructions in Word documents by Microsoft Copilot can cause the hidden instructions in a Microsoft 365 Word document to rewrite numbers in a report and then copy the same instructions to the fi…
Word worm crawls into Copilot, spreads chaos
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog …
Microsoft has integrated its Copilot AI generator into its office suite, which includes office software such as Word and Excel. Now, security researcher Haakon Morley has demonstrated for the first time the effectiveness of a document-based, self-replicating malware, or "AI worm," that targets Copilot for Word. Read more...
Norwegian AI researcher Håkon Måløy has demonstrated how hidden instructions in a Word document can cause Microsoft Copilot to change content, and then copy the attack to new documents. How a Word document can manipulate Microsoft Copilot The attack does not contain malware, macros or traditional program code; instead, it exploits so-called "prompt injection", instructions are hidden in the document with, among other things, white text on a whit…
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








