AI-Powered Worm Exploits Microsoft Copilot's Weakness, Spreads Through Innocent-Looking Word Docs
A security researcher has successfully created a self-replicating worm that hides in Microsoft Word documents and hijacks the company's Copilot AI tool, exposing a significant vulnerability in the system. This exploit has the potential to spread rapidly, compromising sensitive documents and putting user data at risk, with Microsoft having failed to fix the issue after 144 days of being notified.
A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts. The article A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot appeared first on The Decoder.