BotBeat
...
← Back

> ▌

MicrosoftMicrosoft
RESEARCHMicrosoft2026-07-29

Researchers Discover Self-Propagating AI Worms in Microsoft Copilot for Word

Key Takeaways

  • ▸Document-borne AI-worms can self-propagate through Copilot for Word by embedding hidden prompt injection attacks that get copied into newly generated documents
  • ▸The attack exploits normal business workflows—document reuse and collaboration—enabling silent propagation without continued attacker involvement
  • ▸Attack scenarios include manipulation of sensitive documents like financial reports that cascade through organizations as downstream users reuse infected documents
Source:
Hacker Newshttps://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/↗

Summary

Security researcher Canopy9560 has disclosed a significant vulnerability in Microsoft Copilot for Word that enables document-borne AI-worms to self-propagate through normal productivity workflows. The attack exploits Cross-Domain Prompt Injection Attacks (XPIAs) by embedding hidden malicious instructions in documents that are later used as source material with Copilot. When a user includes a compromised document while drafting or editing, the AI interprets the hidden instructions as legitimate requests, alters the generated document, and critically, copies these malicious instructions into the resulting document, turning it into a new attack carrier.

This creates a self-sustaining propagation chain: compromised documents can infect downstream documents used by different users in subsequent Copilot-assisted workflows, without requiring the original malicious document or attacker's involvement. An illustrative scenario shows an employee downloading market analysis from a compromised website, using it with Copilot to draft a financial report that gets altered and infected, then sharing the report internally where colleagues reuse it for further reports—propagating the attack silently through the organization.

The vulnerability was disclosed through a 144-day coordinated disclosure process with Microsoft's Security Response Center (MSRC). At the time of publication, no full customer-side remediation was available; Microsoft advised treating external documents as untrusted and carefully reviewing Copilot-generated content before sharing. This represents among the first public demonstrations of self-replicating AI-worms in mainstream commercial productivity suites.

  • Disclosed through coordinated 144-day MSRC process; no full remediation available at publication, only defensive mitigation practices like treating external documents as untrusted

Editorial Opinion

This discovery reveals a critical vulnerability in AI-assisted productivity workflows: as generative AI embeds deeper into document creation and editing, attackers can weaponize trusted document workflows to propagate malicious instructions without user awareness. Unlike traditional malware requiring active exploitation, these AI-worms spread through normal business practices—document reuse and collaboration—making them uniquely insidious. The finding underscores the urgent need for AI systems to better validate and sanitize external inputs, and for organizations to fundamentally rethink trust models when integrating AI assistants into document workflows.

Generative AIAI AgentsCybersecurityAI Safety & Alignment

More from Microsoft

MicrosoftMicrosoft
OPEN SOURCE

Microsoft Releases Quicksand: Open-Source Sandbox for AI Agents Without Docker or WSL

2026-07-28
MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches AI Security Tools, Claims Performance Advantage Over Competitors

2026-07-28
MicrosoftMicrosoft
PRODUCT LAUNCH

Microsoft Launches Project Perception, an Agentic Security System for AI-Era Threats

2026-07-27

Comments

Suggested

CrackenCracken
OPEN SOURCE

Cracken Releases BlackSea, Open-Source Honeypot to Trap AI-Driven Cyberattackers

2026-07-29
Research CommunityResearch Community
RESEARCH

New Attack Framework Defeats LLM-Based Vulnerability Detectors With Adversarial Code Comments

2026-07-29
AnthropicAnthropic
INDUSTRY REPORT

Microsoft Racing to Patch Vulnerabilities Faster Than Anthropic's Mythos AI Can Discover Them

2026-07-29
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us