cd /news/ai-safety/ai-worming-through-word · home topics ai-safety article
[ARTICLE · art-79150] src=simonwillison.net ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

AI Worming through Word

A new prompt injection attack targets Microsoft Copilot for Word by embedding hidden instructions in documents, causing Copilot to manipulate the document and replicate the instructions into new carriers, enabling self-replication without the original attacker document. The vulnerability was responsibly disclosed to Microsoft, but no comprehensive fix has been released after 144 days.

read1 min views1 publishedJul 29, 2026

An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier. If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker’s original document being present.

We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.

It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack.

Via [Hacker News](https://news.ycombinator.com/item?id=49096188)

Tags: [microsoft](https://simonwillison.net/tags/microsoft), [security](https://simonwillison.net/tags/security), [ai](https://simonwillison.net/tags/ai), [prompt-injection](https://simonwillison.net/tags/prompt-injection), [generative-ai](https://simonwillison.net/tags/generative-ai), [llms](https://simonwillison.net/tags/llms)
── more in #ai-safety 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-worming-through-w…] indexed:0 read:1min 2026-07-29 ·