Hidden prompt turns Microsoft Copilot into an AI worm
ID: 8e569457-a6e5-5efd-b5d3-9c670d9fd13e
STIX ID: report--8e569457-a6e5-5efd-b5d3-9c670d9fd13e
Feed Name: Malwarebytes Blog
A security researcher demonstrated a self‑propagating prompt‑injection “AI worm” targeting Microsoft Copilot for Word: the attack hides JSON‑formatted prompts as white text inside Word documents so Copilot strips formatting, reads the hidden instructions, and appends the malicious prompt into newly created files, enabling stealthy spread through normal document-sharing workflows. Microsoft mitigations (including model upgrades) did not fully prevent reproduction, and the report characterizes the issue as an architectural weakness of current LLM systems; recommended mitigations include treating external documents as untrusted, reviewing Copilot-generated content, and disabling or limiting Copilot where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
