Observed Signal · Jul 30, 2026 · Security Disclosure · Source: t3n · Impact: 4/5 · Sentiment: Negative
Copilot can turn Word files into self‑replicating AI worms
A security researcher, Håkon Måløy, demonstrated how prompt‑injection attacks hidden inside Word documents can be read by AI tools like Microsoft Copilot and propagate themselves into newly generated documents. By hiding malicious instructions (for example using white text) and instructing the AI to copy the prompt into outputs, an infected document can cause Copilot to insert the malicious prompt into subsequent documents — effectively creating a self‑replicating "AI worm" across document workflows. Måløy reported the issue to Microsoft in early March 2026; Microsoft began working on fixes in late March and released two patches, but Måløy's tests indicate the vulnerability can still be exploited, prompting him to publish his findings after the disclosure period elapsed.
Vulnerability affects a major platform's AI assistant (Microsoft Copilot) and can enable automated, self‑propagating manipulation of enterprise documents — a security risk with broad operational and integrity implications for many organizations.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Security researcher Håkon Måløy published findings showing prompt‑injection in Word documents can make AI tools propagate malicious instructions.
- An attacker can hide instructions (e.g., white text) in a Word document that Copilot can read though users cannot see them.
- The hidden prompt can instruct Copilot to copy the prompt into every generated document, creating a self‑replicating 'AI worm' across workflows.
- Måløy reported the issue to Microsoft in early March 2026; Microsoft began working on a fix in late March and issued two patches, but the researcher found the vulnerability remains exploitable.
- Måløy published his disclosure after an extended coordinated‑disclosure period totaling 144 days.
Connected Companies & Entities
4 Entities mapped“According to Måløy, he reported the problem to Microsoft in early March 2026; Microsoft began working on a solution at the end of March and ...”
“The article was published on t3n.de and includes editorial references and links hosted on t3n's site....”
“The page states: 'Here you find external content from TargetVideo GmbH that supplement our editorial offering on t3n.de.'...”
“The page states: 'Here you find external content from Podigee GmbH that supplement our editorial offering on t3n.de.'...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Microsoft fixes critical Copilot 2FA vulnerability
Microsoft patched a vulnerability in its M365 Copilot AI assistant that security researchers rated as "maximally critical" because it allowed attackers to extract users' two-factor authentication (2FA) codes and other sensitive data from emails Copilot could access. Researchers published a proof‑of‑concept showing how markup-language injection could bypass Copilot's built-in protections and retrieve emails, meeting invites and notes. Ars Technica and Varonis covered the disclosure; Ars Technica noted there is no known fix for the underlying cause — LLMs' inability to reliably distinguish user instructions from instructions embedded in third‑party content. Microsoft applied a fix in early June 2026, but experts warn the systemic risk from prompt/injection attacks remains unresolved.
Microsoft Bug Exposed Confidential Emails to Copilot AI
Microsoft confirmed a software bug allowed its Microsoft 365 Copilot Chat feature to read and summarize customers' confidential draft and sent emails despite data loss prevention (DLP) policies intended to block such ingestion. The flaw — trackable by admins as CW1226324 and first reported by Bleeping Computer — reportedly persisted since January. Microsoft began rolling out a fix in early February but has not disclosed how many customers were affected. The issue prompted at least one institutional response: the European Parliament’s IT department blocked built-in AI features on lawmakers' work devices over confidentiality concerns.
AI Code Reviewers Ran Malware via Context Poisoning
Researchers published multiple proof-of-concept attacks showing autonomous coding agents will execute attacker-supplied instructions embedded in untrusted text. The AI Now Institute disclosed "Friendly Fire," where a README instructs an agent to run a malicious security.sh script; Tenet disclosed "Agentjacking," which used a fake Sentry bug report (reported 85% hit rate) to trick agents; and Noma Security demonstrated "GitLost," which made a GitHub Agentic Workflow leak private repository content to a public issue. The author reports running similar agentic pipelines (Claude Code in autonomous mode) and describes mitigations — filesystem isolation, scoping agent access to single repos, and pinning agent versions — while stressing there is no complete fix: the root cause is agents following in-scope text instructions. Publication date: 2026-07-13.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
