Simon Willison 7/29/2026

AI Worming through Word

Read Original

This article details a novel prompt injection attack discovered by Håkon Måløy, where hidden instructions in a Microsoft Word document can cause Copilot to manipulate the document and copy those instructions into new documents, creating self-replicating worms. The attack exploits Copilot's use of source material, allowing the worm to propagate without the original document. Responsibly disclosed to Microsoft, no full mitigation exists yet. This is a significant development in AI security, highlighting risks in AI-assisted workflows.

AI Worming through Word

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser