A researcher has identified an "AI worm" vulnerability in Microsoft Copilot that allows malicious instructions to spread through Word documents, potentially compromising enterprise data and document integrity.
Key Points
- Researcher Håkon Måløy discovered that malicious prompts hidden in Word documents can trigger Copilot to alter data and embed itself into new files.
- The vulnerability functions as a self-propagating malware pattern that bypasses traditional email security, data loss prevention (DLP), and endpoint protection tools.
- Microsoft has implemented several mitigations following coordinated disclosure but has not yet fully resolved the core issue of separating data from instructions.
- Security experts warn that the flaw could allow corrupted financial reports or contracts to circulate within organizations while retaining a veneer of legitimacy.
- Recommended defenses include restricting Copilot’s auto-discovery features, requiring human approval for AI-generated changes, and tracking AI-touched content via document metadata.