Safety · The Decoder ·
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
A security researcher demonstrated a self-spreading prompt-injection attack targeting Microsoft Copilot for Word. Malicious instructions hidden in documents can propagate into new files when reused; Microsoft confirmed the issue but had not fixed it after 144 days and two attempts.