Skip to content
Hacker News front page

Document-borne AI worms can self-propagate through Copilot for Word

Researcher Håkon Måløy disclosed an actively exploitable document-borne AI worm in Microsoft Copilot for Word. Hidden instructions in a source document cause Copilot to alter the output and copy the attack into the new file, which then infects further documents. Microsoft deployed two mitigations over a 144-day coordination window, including a model upgrade, but neither closed the vulnerability class. No robust fix is available at publication.

Why it matters: A security researcher disclosed a working document worm in Copilot for Word with full PoC and coordinated MSRC disclosure — high signal density. Points off because it's a personal blog first, not an official Microsoft advisory, and the attack requires specific environmental as...

Read the original ↗Export Markdown