Theregister Self-Propagating AI Worm Discovered in Microsoft Word Copilot
Article Content
- •A self-propagating worm can alter documents and spread through Microsoft Word Copilot.
- •The vulnerability allows hidden malicious instructions without needing access to the victim's tenant.
- •Microsoft's mitigation efforts have failed to close the broader vulnerability class.
A critical vulnerability in Microsoft Copilot for Word allows hidden malicious prompts in documents to alter generated content and spread to new files. Disclosed by researcher Håkon Måløy, this issue, termed 'Context Collapse, Part 3 – AI Worming through Word,' has persisted despite Microsoft's mitigation attempts since March 2026. The vulnerability enables attackers to exploit untrusted documents without requiring access to a victim's Microsoft 365 tenant. Måløy's research indicates that the worm can propagate through normal workflows, making it difficult to trace its origin. Microsoft has acknowledged the issue but has not yet provided a robust solution. The attack vector relies solely on the inclusion of a compromised document in Copilot's context. The situation remains urgent as the worm continues to pose a significant risk to businesses using Microsoft Word.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…