importantSYS.SOURCE: En Klype Salt• 2026-07-29T11:44:33Z
AI Worm Propagation via Document Workflows in Microsoft Copilot for Word
This article describes a self-propagating AI worm vulnerability in Microsoft Copilot for Word, where malicious instructions in documents can be copied into generated content, enabling cross-domain prompt injection attacks. The vulnerability was disclosed after 144 days of coordinated efforts with Microsoft, with no robust mitigation available at publication.
*** END OF TRANSMISSION ***