Switch language한국어
Back to the list

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

TL;DR AI

Key summary

2 min read
  1. Security researcher Håkon Måløy showed that hidden text in a Word document can be read by Microsoft Copilot and copied into a new document.

  2. That makes the attack self-spreading: when the file is reused as a source or template, the malicious instructions can propagate.

  3. Microsoft confirmed the issue, but two fix attempts failed and no patch was available when the findings were published.

  4. The demo shows prompt injection can behave like a worm, creating a practical security risk for document workflows and enterprise users.

Read the original