Microsoft confirms Copilot worm can spread through Word documents via malicious source material Microsoft confirmed that attackers can hide instructions in Word documents used as source material for its Copilot AI, allowing a worm to spread through the AI's processing of malicious documents, as reported by CSO Online. Norwegian AI researcher Håkon Måløy reported the vulnerability, which expands the attack surface for Copilot deployments in enterprise environments by infecting documents consumed by the AI rather than exploiting a direct application vulnerability. Microsoft confirms Copilot worm can spread through Word documents via malicious source material According to CSO Online, Norwegian AI researcher Håkon Måløy reported and Microsoft confirmed that attackers can hide instructions in Word documents used as source material for Copilot, causing the AI to execute those concealed instructions. The attack vector allows infection through documents consumed by the AI rather than direct application vulnerability, expanding the attack surface for Copilot deployments in enterprise environments. Topics Sources - Press Read article https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs/ Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.