A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot Security researcher Michael Bargury demonstrated a self-spreading worm that hides prompt injections inside Word documents and hijacks Microsoft Copilot, automatically spreading to new files when reused. Microsoft confirmed the vulnerability but failed to fix it after 144 days and two attempts. A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts. The article A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot/ appeared first on The Decoder https://the-decoder.com .