AI Signal 175
AI Worming through Word
This turns a known vulnerability class (prompt injection via hidden text) into a self-sustaining threat that can spread between documents and users without the original attacker's document present. Microsoft has had 144 days since responsible disclosure and still lacks a mitigation for the full attack class, meaning any Copilot-for-Word workflow that processes untrusted documents remains exposed.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Hidden instructions in a Word document can cause Copilot for Word to both execute those instructions and copy them into output documents, enabling self-replication.
The attack propagates when a newly infected document is used in another Copilot-assisted workflow, even without the attacker's original document.
Microsoft was given 144 days of responsible disclosure but has not yet shipped a mitigation covering the full class of attack.
THE CLUSTER