A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
What happened
A security researcher created a self-propagating worm that lives inside Microsoft Word documents. This worm uses invisible prompt injections to hijack Microsoft Copilot’s AI assistant embedded in Word. Each time an infected document is reused or shared, the worm spreads into new files automatically, without user awareness. Microsoft acknowledged the vulnerability but failed to fix it despite 144 days passing and two attempts to patch the issue.
The risk
This exploit undermines document safety by weaponizing the Copilot AI with hidden commands embedded inside files. Traditional document sharing now doubles as a vector for AI prompt injections that modify or control how Copilot interprets user input. The worm spreads silently and continuously, making it harder to detect and contain. Microsoft’s slow response increases the window of exposure for enterprises relying on Word and Copilot integration.
Why it matters
For businesses and operators using Microsoft Copilot, this attack raises the risk profile of trusted documents. Worms embedded in files can push malicious or misleading AI-generated results without explicit user action. This weakens trust in AI-enhanced productivity tools, forcing IT teams to rethink security controls around AI prompts and document management. It also stresses the need for improved prompt sanitation and stronger AI system safeguards before broad deployment in enterprise workflows.
Who should pay attention
Security teams, enterprise IT, compliance officers, and anyone managing sensitive documents in organizations that use Microsoft Copilot must be alert. Developers embedding AI agents in user-generated content platforms should treat prompt injection as a severe threat vector. Vendors offering AI assistants integrated into file-based workflows must prioritize prompt hygiene and adopt real-time detection to prevent similar worm propagation.
What to watch next
Watch how Microsoft updates its Copilot platform or Word to address invisible prompt injections and worm-like propagation. Monitor whether the ongoing delays in fixes impact enterprise confidence or adoption speeds. Observe if other AI assistant providers face similar vulnerabilities with embedded prompt injection attacks and how they respond operationally and technically.
AI Quick Briefs Editorial Desk