Skip to content
Microsoft 365 Copilot Word worm survives model updates

Microsoft 365 Copilot Word worm survives model updates

Feeds.4Sysops IT News July 30, 2026

A self-propagating Word worm can still alter documents and copy hidden instructions into new files after Microsoft 365 Copilot mitigations, including a model upgrade, failed to close the broader vulnerability class. The attack requires no macros, executable code, or access to a victim’s Microsoft 365 tenant—only a malicious document that enters Copilot’s context. Source

Extracted Entities

Attack Types (1)