A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

AI Summary
A security researcher has created a self-spreading worm that embeds invisible prompt injections within Word documents, which exploit Microsoft Copilot. Microsoft acknowledged the vulnerability but has not resolved the issue after 144 days and two attempts.
From the source
A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts. The article A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot appeared first on The Decoder.
The full text couldn't be loaded here (the source may require a subscription).
View original at The Decoder