Microsoft Word Copilot Vulnerability Enables Self-Propagating AI Worms

Microsoft Word Copilot Vulnerability Enables Self-Propagating AI Worms

First seen 30 Jul 2026, 08:20 UTC TheregisterCybersecuritynewsGbhackers 81% similarity 66.0

Article Content

Browse articles
ThreatCluster

A vulnerability in Microsoft Copilot for Word allows hidden prompts in documents to create self-propagating AI worms that can tamper with business content. Researcher Håkon Måløy disclosed the issue after months of coordination with Microsoft, revealing that no robust mitigation is currently available. The attack vector involves malicious instructions embedded in documents that alter outputs and replicate themselves across new files. This vulnerability affects users of Microsoft 365, as the attacker only needs to share a compromised document. Måløy's research indicates that the worm can spread without further involvement from the attacker after initial infection. The issue has been publicly disclosed after 144 days of testing and attempts at mitigation, which have proven ineffective.

Key Points: • A new vulnerability in Microsoft Copilot for Word allows self-propagating AI worms. • Malicious instructions in documents can alter outputs and replicate across new files. • No robust mitigation has been achieved despite months of coordination with Microsoft.

ThreatCluster AI How this analysis works

Timeline

2026-03-01
Coordination with Microsoft begins
Researcher Håkon Måløy starts working with Microsoft to address the vulnerability discovered in Copilot.
Theregister
2026-07-29
Vulnerability disclosed
Håkon Måløy publicly discloses the Copilot vulnerability after 144 days of testing and coordination with Microsoft.
Theregister
2026-07-30
Cybersecurity news coverage
Cybersecuritynews reports on the Copilot vulnerability, highlighting its potential impact on business content.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story