Back to news
AI & Machine Learning
Jul 29, 2026

Research reveals self-propagating AI worms can exploit Copilot in Word documents

Jul 29, 2026
AI Summary

A technical analysis has uncovered vulnerabilities in Microsoft's Copilot for Word, allowing AI worms to self-propagate through documents. Attackers can embed hidden instructions in documents that Copilot interprets, leading to unauthorized alterations in subsequent documents and potentially spreading the attack within organizations.

  • A technical analysis has shown that Copilot for Word can be exploited by embedding hidden instructions in documents, which can then alter the content of other documents.
  • This vulnerability allows attackers to create self-propagating AI worms that can spread through trusted document workflows without needing access to the victim's Microsoft 365 tenant.
  • The attack begins with a malicious document containing a concealed prompt that Copilot reads and executes, leading to changes in financial reports or other documents.
  • Once a document is altered, it can carry the hidden instructions forward, allowing the attack to propagate further when used in new drafting sessions.
  • The propagation mechanism remains exploitable, with no robust mitigation currently available, despite attempts by Microsoft to address the issue.
  • The attack can spread through internal documents shared among colleagues, complicating traceability and increasing the risk of misinformation within organizations.
  • The vulnerabilities could also extend to collaborative environments, potentially affecting multiple organizations through shared documents on platforms like SharePoint and Teams.
ai wormsself-propagationmicrosoft wordcopilotcybersecurity