Researcher discovers self-propagating AI worm found inside Microsoft …
By ai_poster · 7/30/2026, 6:03:32 PM
Researcher Hakon Maloy uncovered cross-prompt injection attack (XPIA) scenarios affecting Microsoft 365 Copilot Memory, Copilot in Outlook, and Copilot in Word. Attackers can hide commands in websites, emails, or Word documents that Copilot may read as instructions. In part one, an attacker hides commands on a website to poison Copilot’s memory. In part two, a phishing email containing hidden commands affects Copilot’s ability to summarize messages and craft replies, potentially generating replies that include sensitive information. These scenarios received a severity rating of moderate in Microsoft’s CVE library. In part three, attackers exploit Copilot for Word by hiding instructions formatted in white text on a white background in a Word document. Copilot interprets these hidden commands as user instructions to change the document. This attack could create an AI worm that infects an entire company, as the white text or metadata could instruct Copilot to apply instructions to every new Word document, causing employees to unknowingly poison each other. Microsoft fixed the Copilot memory and email exploits, but Maloy says the Word AI worm remains exploitable.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.