Mark RadarMARK RADAR
About
EN
Sign in

Researchers Expose Self-Propagating AI Worm in Microsoft Copilot

1 reports · First detected 2026-08-05 · Last active 2026-08-05

As generative AI assistants become embedded in Microsoft 365 workflows, prompt injection is evolving from a one-off manipulation technique into a potential propagation mechanism. Researchers found that attackers can conceal malicious instructions inside Word documents and influence Microsoft Copilot when it processes the files. Because the technique does not require macros or conventional malware, it may evade security controls designed to detect executable code and suspicious attachments.

The researchers demonstrated an AI worm that can prompt Copilot to copy hidden instructions into newly created or edited Word files, allowing the payload to spread through ordinary document activity. The attack relies on Copilot interpreting concealed content rather than users running malicious software. As of Aug. 5, 2026, Microsoft had issued mitigation measures, but the researchers said the changes had not fully eliminated the underlying risk of self-propagating prompt injection.

All Coverage

1 original reports

The Backstory

The history behind this event
Major Microsoft Copilot Cowork Flaw Lets Prompt Injection Leak Corporate Secrets2026-05-26 · 1 reports · similarity 0.82

Microsoft 365 Copilot Cowork is an AI agent that can handle enterprise workflows on users’ behalf and access internal data in SharePoint, OneDrive and other services. Because the agent can invoke tools and send messages autonomously, a prompt injection that bypasses permission boundaries could expose not only chat content but also corporate secrets and undermine cloud-file governance.

Cybersecurity firm PromptArmor recently disclosed that attackers could hide malicious instructions in skill files, prompting Copilot Cowork to automatically run a workflow that sends a message to the user and redirects sensitive-file download links to an attacker-controlled server. The number of affected companies, financial losses and exact public disclosure date have not been revealed. The key risk is that data can be exfiltrated without the user’s knowledge.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)