cd /news/ai-safety/a-security-researcher-built-a-self-s… · home topics ai-safety article
[ARTICLE · art-83032] src=the-decoder.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

Security researcher Michael Bargury demonstrated a self-spreading worm that hides prompt injections inside Word documents and hijacks Microsoft Copilot, automatically spreading to new files when reused. Microsoft confirmed the vulnerability but failed to fix it after 144 days and two attempts.

read1 min views1 publishedAug 1, 2026

A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts.

The article A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot appeared first on The Decoder.

── more in #ai-safety 4 stories · sorted by recency
── more on @michael bargury 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-security-researche…] indexed:0 read:1min 2026-08-01 ·