Skip to content
The Nexus
SECURITYJul 30 · 12:58 UTCMALWAREBYTES LABS

Hidden prompt turns Microsoft Copilot into an AI worm

A security researcher demonstrated how Microsoft Copilot for Word can be exploited via a hidden JSON-formatted prompt embedded in white text on a white background within Word documents. The attack allows the prompt to propagate through document-sharing workflows as Copilot processes the hidden instructions, modifying documents and appending malicious prompts without user awareness. Microsoft's mitigations, including newer GPT models, have not fully resolved the vulnerability, which stems from an architectural weakness in LLM systems.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting