All posts

Microsoft confirms AI worm spreading through Copilot

Manaal KhanAugust 16, 2026 at 2:47 PM4 min read
Microsoft confirms AI worm spreading through Copilot

An attacker can hide instructions inside a Word document that spread automatically when Microsoft Copilot uses that file as source material. Norwegian AI researcher Håkon Måløy published proof on Tuesday, and Microsoft confirmed the vulnerability Thursday, calling it a "class of risk" the company is addressing with layered defenses.

Microsoft confirms AI worm spreading through Copilot
Source: Computerworld

The attack works like this: malicious instructions concealed in a document get processed by Copilot when a user asks the AI assistant to generate or edit a new file. Those instructions can alter figures in the output, then copy themselves into the new document. That document becomes a carrier, infecting the next Copilot-assisted workflow. Måløy called it "among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite."

Advertisements

Why existing defenses fail

Hidden Prompt Attack Turns Microsoft Copilot into AI Worm | VARINDIA News Hour

Aman Mahapatra, chief strategy officer at New York-based consulting firm Tribeca Softtech, reviewed the attack mechanism and argued it sidesteps nearly every enterprise security control.

"This is a worm, a self-propagating malware pattern that uses Copilot as the transmission mechanism and legitimate corporate collaboration as the delivery channel," Mahapatra said. The document is not malicious on arrival. It becomes malicious only when Copilot processes it.

That sequence breaks email security filters, which scan attachments at delivery. It evades data loss prevention tools because exfiltration happens through the user's own authenticated Copilot session. And it bypasses endpoint protection because no code executes. The AI simply follows instructions the enterprise already authorized it to follow.

Mahapatra noted that researchers have warned about this class of attack for two years.

Microsoft's response so far

Måløy has been working with the Microsoft Security Response Center since March 3. Microsoft distributed multiple small mitigations, but the core vulnerability remains unfixed.

"We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure," Microsoft said in a statement to CSOonline. "To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points."

Microsoft urged customers to install the latest updates, use multiple security layers, treat content from unknown sources with caution, and review AI-generated content before sharing it.

Måløy said he was hesitant to disclose an active vulnerability but decided defenders needed awareness. "Defenders cannot reduce exposure to a risk they are unaware of," he wrote, "and the propagation mechanism described here affects ordinary document workflows that many organizations already rely on."

Why separating instructions from data is not simple

Some analysts have suggested LLMs should fully isolate instructions from the data they operate on. Måløy pushed back on this as a complete fix.

"The distinction between data and instructions is not always clear in real-world workflows," he said. A user might ask an AI agent to arrange a business trip, requiring it to retrieve an email with the approved itinerary and a document containing the booking procedure. Both contain instructions the agent must follow.

"The broader challenge is therefore not simply to prevent systems from interpreting external content as instructions, but to evaluate whether those instructions align with the user's goals and the context in which the system is operating," Måløy added.

ℹ️

Logicity's Take

This is a turning point for enterprise AI adoption. Security teams built their defenses around the assumption that malicious content arrives from outside. Here, the threat propagates through sanctioned tools and authenticated sessions. Organizations deploying Copilot, or competitors like Google Duet AI, need to audit what documents feed into AI-assisted workflows and establish review gates before AI-generated outputs get shared downstream. The mitigations Microsoft has shipped reduce reliability of the attack but do not close it. Expect AI-focused security vendors to build detection for this class of threat within weeks.

What enterprises should do now

Mike Wilkes, enterprise CISO at Aikido Security, said the potential impact is difficult to overstate. "This moves prompt injection from a single compromised interaction into a potentially self-propagating document."

Until Microsoft delivers a deeper fix, CIOs and IT leads should consider three steps: flag documents from external or unknown sources before they enter Copilot workflows, require human review of AI-generated outputs that feed into other AI tasks, and monitor Copilot activity logs for unusual patterns in document processing chains.

Also Read
Amex GBT brings full travel booking to Claude

Another example of enterprise AI integration and the security surface it creates

The coordinated disclosure showed mitigations can reduce the attack surface without eliminating it entirely. But the window between "less reliable" and "fixed" is where attackers tend to move fastest.

ℹ️

Need Help Implementing This?

If your organization uses Microsoft Copilot and you need help assessing your exposure to document-borne AI threats, reach out to our editorial team for vendor-neutral guidance and security audit recommendations.

Source: Computerworld

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.