Hidden Word Prompts Turn Microsoft Copilot Into an AI Worm Vector
Researchers demonstrated an AI worm that embeds hidden instructions in Microsoft Word documents and uses Copilot to reproduce them in newly generated or edited files. The instructions can manipulate document content and spread through legitimate collaboration workflows without executing conventional malware code, potentially bypassing email security, DLP, and endpoint protection. Microsoft said it has implemented multiple safeguards and continues strengthening its defenses, although the researcher maintains that the underlying separation problem between trusted instructions and untrusted document data remains unresolved. Organizations should install current updates, limit untrusted source documents, apply layered security controls, and review AI-generated content before sharing it.
Reference: csoonline.com