AI Safety 🇷🇺 30.07.2026 10:03

AI worm discovered that spreads via Microsoft Copilot through hidden prompts in Word

MicrosoftMicrosoft
Norwegian data analyst Håkon Måløy discovered an AI worm that spreads through hidden prompts in Word documents, causing Microsoft Copilot to alter data and replicate. Microsoft was notified in March 2026, but the vulnerability persists; no complete fix exists yet.
Håkon Måløy reported a vulnerability in Microsoft Copilot where a hidden prompt in a Word document can make the AI modify data and self-replicate. This is one of the first public demonstrations of a self-propagating AI worm through office documents. Microsoft and Måløy have been working since March 2026 to fix the issue, but the malicious mechanism still works. Initially Microsoft patched the specific exploit, but a rephrased prompt bypassed the fix. After 144 days without resolution, Måløy decided to disclose the vulnerability publicly without releasing the actual malicious prompt. The attack works when a user, e.g., preparing a financial report, downloads a compromised file from a trusted site; Copilot then alters numbers and copies the malicious instructions to new files. Other employees using the doctored file continue the propagation. The attack requires only sending the document to a victim; no further access to the compromised site or Microsoft 365 client is needed. Copilot is fundamentally not supposed to execute instructions from document content, but it sometimes does. Long-term solution requires separating goals and intentions from processed information, but currently the only guaranteed protection is to avoid using Copilot or to treat all external documents as untrusted. Microsoft acknowledged the issue, thanked the researcher, and emphasized multi-layered defense and customer caution.
Source: 3DNews — original
Our earlier posts on this topic ↓
Fresh news