Skip to content
ATAI Today Brief
HomeNewsConceptsGuidesToolbox
AboutSubscribeUA
Subscribe

AI Today Brief

The daily AI-engineering brief. Built in public. EN · UA.

XTelegramLinkedInYouTubeRSS

Follow AI Today Brief on LinkedIn for daily AI-engineering updates and the weekly “5 shifts that changed how developers work” PDF.

Explore

NewsDigestsConceptsGuides

Company

SubscribeAdvertiseAbout

Legal

Editorial policyAI disclosurePrivacyTerms

© 2026 AI Today Brief. All rights reserved.

  1. Home/
  2. News/
  3. Agents & MCP/
  4. Copilot Worm Demonstrates Self-Propagating Prompt Injection in Word Documents
Agents & MCP

Copilot Worm Demonstrates Self-Propagating Prompt Injection in Word Documents

August 3, 2026· 4 min read
OKCurated by Oleksandr Kuzmenko, AI Product Engineer·Updated August 3, 2026·Sources cited on every story
AI-assisted · editor-reviewed·How we use AI
Copilot Worm Demonstrates Self-Propagating Prompt Injection in Word Documents

Researchers demonstrated an AI worm that uses Microsoft Copilot as a vector to spread malicious instructions through Word documents. The injected instructions alter figures and copy themselves into new documents during normal enterprise workflows.

Impact: High

Why it matters

Engineers and security leads must review AI-assisted generation workflows to protect internal documents from indirect prompt injection.

TL;DR

  • 01Copilot can propagate hidden instructions across enterprise Word documents.
  • 02Indirect prompt injection bypasses traditional email security and DLP controls.
  • 03Treat AI-generated text and unknown incoming source documents with strict caution.

Key facts

Disclosure Date
March 3 (Coordinated)
Vector
Microsoft Word Document / Copilot

The Mechanics of Document-Borne AI Worms

Reported by a Norwegian AI researcher and confirmed by Microsoft, an attacker can conceal malicious instructions inside a Word document. When Copilot processes this document as source material (e.g., input for a financial report), the instructions can alter figures and append themselves to the output document.

Enterprise Security Implications

Industry experts note that this attack pattern bypasses traditional security controls:

  • Email Security: Bypassed because the delivery document appears legitimate.
  • Data Loss Prevention (DLP): Exfiltration occurs via the user's authenticated session.
  • Endpoint Protection: No traditional code executes; the AI service simply follows hidden text instructions.

Vendor Mitigations and Future Fixes

Microsoft confirmed a defense-in-depth strategy, deploying multiple safeguards to block malicious instructions. However, security experts emphasize that solving the underlying instruction-data confusion at the model level remains an industry-wide challenge.

What to do today

  • →Review AI-assisted document editing workflows for third-party source files.
  • →Ensure Office apps and Copilot environments are updated with latest security patches.
#Microsoft Copilot#Microsoft Word#Microsoft 365

Sources

  • Copilot worm can spread through Microsoft Word docs
ShareShare on XShare on LinkedIn
← Previous storyJFrog Exposes Batch of Fabricated SQLite CVEs Generated by LLMs

Related stories

  • Agents & MCPConvert Technical Books and Specs into Agent Skills with book-to-skill
  • Agents & MCPOrchestrating Technical Documentation via Claude Code Agent Skills and Forensics
  • Agents & MCPNightcrawler Deploys Autonomous Local Model Context Protocol Pentesting Agents to Mobile Devices
  • Agents & MCPBlock Releases Buzz: Self-Hosted Nostr Workspace for Human and AI Agent Collaboration

Email digest

Get the morning AI brief

One email a day — the stories that matter for engineers, founders and tech leads. Human-edited, with links to primary sources.

  • ✓120+ sources scanned daily
  • ✓Edited by a human
  • ✓1 email per day
  • ✓EN + UA

By subscribing you agree to the privacy policy.