Document-borne AI worms can self-propagate through Copilot for Word
12 hours ago
- Attackers can embed hidden instructions in Word documents that cause Microsoft Copilot to alter content and propagate the attack to new documents, creating a self-replicating AI worm.
- The attack exploits the trust boundary between attached documents and the current drafting document, as Copilot treats all text in its context as potentially authoritative.
- No robust mitigation exists for the broader vulnerability class; Microsoft's fixes closed specific payloads but not the underlying architectural weakness.
- Once propagated, the attack becomes difficult to trace because affected documents are created by legitimate users and may spread across organizations via shared SharePoint or Teams.
- The underlying issue is that LLMs cannot reliably separate attacker-controlled content from trusted instructions, a fundamental architectural challenge in current AI systems.