Researcher discovers self-replicating prompt injection in Microsoft Word
Security researcher Håkon Måløy found a prompt injection variant that turns Word documents into self-replicating worms, copying hidden instructions across Copilot-assisted workflows without the attacker's original file.
Håkon Måløy has discovered a prompt injection attack that transforms Microsoft Word documents into self-replicating worms. The attack works by embedding hidden instructions in a document that Copilot interprets as user commands, causing the AI to manipulate the output and copy the malicious instruct...
Sign in to read the full analysis
Free account. Full analysis on LLM unit economics, plus the weekly Cost-of-Inference column.
Try it on your own context
You just read the writeup. Now run the thing. Paste a doc or some verbose tool output and watch it shrink — free, no signup.
- Source type
- Primary publication (lab/vendor blog) — our analysis + implication
- Source link
- Simon Willison
- Published
- UTC
- Byline
- By the gotcontext.ai team (editorial standards)
- Correction?
- corrections@gotcontext.ai