Safety · The Decoder ·

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

A security researcher demonstrated a self-spreading prompt-injection attack targeting Microsoft Copilot for Word. Malicious instructions hidden in documents can propagate into new files when reused; Microsoft confirmed the issue but had not fixed it after 144 days and two attempts.

Read the full story at The Decoder →