AI Worming through Word
ai
A researcher named Håkon Måløy has discovered a troubling self-replicating vulnerability in Microsoft Word's Copilot feature. According to Simon Willison's Weblog, the attack works by embedding hidden instructions in documents. When Copilot processes these documents, it misinterprets the hidden text as legitimate user commands, manipulating the file being edited. Worse, Copilot also copies the hidden instructions into newly created documents, allowing the attack to chain forward to other users and workflows. Microsoft received notification one hundred forty-four days ago, but no complete fix has been released.
Source: https://simonwillison.net/2026/Jul/29/ai-worming-through-...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton