Microsoft confirms Copilot worm can spread through Word documents via malicious source material
According to CSO Online, Norwegian AI researcher Håkon Måløy reported and Microsoft confirmed that attackers can hide instructions in Word documents used as source material for Copilot, causing the AI to execute those concealed instructions. The attack vector allows infection through documents consumed by the AI rather than direct application vulnerability, expanding the attack surface for Copilot deployments in enterprise environments.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.