Hasty Briefsbeta

Bilingual

Document-borne AI worms can self-propagate through Copilot for Word

12 hours ago
  • Attackers can embed hidden instructions in Word documents that cause Microsoft Copilot to alter content and propagate the attack to new documents, creating a self-replicating AI worm.
  • The attack exploits the trust boundary between attached documents and the current drafting document, as Copilot treats all text in its context as potentially authoritative.
  • No robust mitigation exists for the broader vulnerability class; Microsoft's fixes closed specific payloads but not the underlying architectural weakness.
  • Once propagated, the attack becomes difficult to trace because affected documents are created by legitimate users and may spread across organizations via shared SharePoint or Teams.
  • The underlying issue is that LLMs cannot reliably separate attacker-controlled content from trusted instructions, a fundamental architectural challenge in current AI systems.