{"id":8945,"date":"2026-07-31T01:13:39","date_gmt":"2026-07-31T01:13:39","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8945"},"modified":"2026-07-31T01:13:39","modified_gmt":"2026-07-31T01:13:39","slug":"microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8945","title":{"rendered":"Microsoft confirms an AI worm is propagating through Copilot and other MS apps"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/enklypesalt.com\/posts\/context-collapse-part3-ai-worming-through-word\/\" target=\"_blank\" rel=\"noopener\">The report<\/a> from noted Norwegian AI researcher <a href=\"https:\/\/www.linkedin.com\/in\/h%C3%A5kon-m%C3%A5l%C3%B8y-770572276\/\" target=\"_blank\" rel=\"noopener\">H\u00e5kon M\u00e5l\u00f8y<\/a>, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word documents, for example, as input to a financial report. Those malicious instructions could potentially alter figures in the document being created. They then copy themselves into the new document, causing it to become a carrier of the attack when used in another Copilot-assisted workflow.<\/p>\n<p class=\"wp-block-paragraph\">M\u00e5l\u00f8y noted: \u201cTo my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Microsoft on Thursday emailed a statement to CSOonline discussing the report\u2019s revelations.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users\u2019 requests,\u201d Microsoft said. <\/p>\n<p class=\"wp-block-paragraph\">\u201cWe are continuously strengthening these safeguards as the technology and threat landscape evolve,\u201d it added. \u201cWe encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.\u201d\u00a0<\/p>\n<h2 class=\"wp-block-heading\">Sidesteps defenses<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/akm76\/\" target=\"_blank\" rel=\"noopener\">Aman Mahapatra<\/a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, has reviewed the mechanisms used in this vulnerability and says that it is much worse than it might seem, because it will sidestep just about every defensive mechanism enterprises have in place today.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is a worm, a self-propagating malware pattern that uses Copilot as the transmission mechanism and legitimate corporate collaboration as the delivery channel. It bypasses every traditional email security control because the document is not malicious on delivery and it becomes malicious when Copilot processes it. That means that it bypasses DLP because the exfiltration happens through the user\u2019s own authenticated Copilot session,\u201d Mahapatra said. \u201cIt then bypasses endpoint protection because no code executes, only instructions get followed by an AI service the enterprise has explicitly authorized.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He also noted that researchers have been warning about this class of attack for two years.<\/p>\n<h2 class=\"wp-block-heading\">Microsoft\u2019s involvement<\/h2>\n<p class=\"wp-block-paragraph\">M\u00e5l\u00f8y said that he has been working with the Microsoft Security Response Center (MSRC) since March 3 and <a href=\"https:\/\/www.csoonline.com\/article\/4203349\/russian-hackers-turn-exchange-flaw-into-half-click-mailbox-takeover.html\" target=\"_blank\" rel=\"noopener\">Microsoft <\/a>\u00a0subsequently implemented and distributed multiple small focused mitigations, but the core vulnerability has yet to be fixed.<\/p>\n<p class=\"wp-block-paragraph\">He said he was hesitant to disclose an active vulnerability, but felt that it was now time to publish.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cMy reasoning is that defenders cannot reduce exposure to a risk they are unaware of,\u201d M\u00e5l\u00f8y wrote, \u201cand the propagation mechanism described here affects ordinary document workflows that many organizations already rely on.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In an email interview, M\u00e5l\u00f8y noted that the tweaks Microsoft has implemented were helpful, nonetheless.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe coordinated disclosure process showed that mitigations can meaningfully reduce the demonstrated attack surface, making attacks less reliable and limiting their reach, even without completely eliminating the underlying problem,\u201d he said.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">M\u00e5l\u00f8y also addressed the resolution that many analysts and consultants suggested, which is to change the nature of LLMs to fully isolate instructions from the data they operate on.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSeparating instructions from data may be part of the solution, but I think the distinction between data and instructions is not always clear in real-world workflows. For example, a user may ask an agent to arrange a business trip, requiring the agent to retrieve an email specifying the approved itinerary and a document containing the booking procedure,\u201d M\u00e5l\u00f8y said. <\/p>\n<p class=\"wp-block-paragraph\">\u201cMy view is that the broader challenge is therefore not simply to prevent systems from interpreting external content as instructions, but to evaluate whether those instructions align with the user\u2019s goals and the context in which the system is operating,\u201d he added.<\/p>\n<h2 class=\"wp-block-heading\">Problem hard to overstate<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/eclectiqus\/\" target=\"_blank\" rel=\"noopener\">Mike Wilkes<\/a>, enterprise CISO at Aikido Security, said it would be difficult to overstate the potential problems from this situation.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is a significant issue because it moves prompt injection from a single compromised interaction into a potentially self-propagating document integrity attack,\u201d he said, noting that it is not a conventional worm that spreads automatically. A user or Copilot workflow must still bring an infected document into the model\u2019s context. \u201cBut once that happens, the malicious instructions can reportedly alter business information, conceal themselves inside the resulting Word document and turn a legitimate internal file into the next carrier,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">That, he pointed out, creates \u201ca dangerous enterprise supply chain in which financial reports, contracts, policies and partner documents may inherit malicious behavior while retaining the trust associated with their legitimate authors and Microsoft 365 accounts.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Not a new issue<\/h2>\n<p class=\"wp-block-paragraph\">The key issue behind this flaw is the fact that genAI tends to struggle with telling the difference between data that a user offers as input and the instructions the AI is to execute.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/fvillanustre\/\" target=\"_blank\" rel=\"noopener\">Flavio Villanustre<\/a>, CISO for the LexisNexis Risk Solutions Group, observed that the same problem with mixed data and instructions occurred in databases decades ago, and turned into what we know as SQL injection attacks today. But, he noted, a few years later, parametrized binding for the database access layers was developed, which separates instructions, which are handled internally and safely, from data, which can come from untrusted sources. \u201cThe same needs to happen with LLMs and other AI,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/moorinsightsstrategy.com\/team\/mike-leone\/\" target=\"_blank\" rel=\"noopener\">Mike Leone<\/a>, a VP\/principal analyst at Moor Insights &amp; Strategy, agreed.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s hard not to chuckle a bit with this one. People have been asking whether data can give orders since SQL injections. We fixed that one by giving the database a way to tell an instruction from a value,\u201d Leone said. \u201cThirty years later, we\u2019ve built an entire category of software that can\u2019t tell the difference at all.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/tomfindling\/\" target=\"_blank\" rel=\"noopener\">Tom Findling<\/a>, CEO at Conifers.ai, also said he sees the data-vs-instructions issue as the biggest problem.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSeparating data from instructions is still unsolved at the model layer. The labs are making real progress, but not enough to be your only control,\u201d he said, and stressed, \u201cMicrosoft doesn\u2019t need to wait for that. It can slow propagation inside Copilot: stop hidden content from being written into new documents, surface hidden text before it\u2019s used, preserve the trust level of what Copilot read and show all AI-generated changes.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Fix needs industry agreement<\/h2>\n<p class=\"wp-block-paragraph\">However, <a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF004767\" target=\"_blank\" rel=\"noopener\">Frank Dickson<\/a>, group VP for security at IDC, argued that a fix needs industry agreement.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cA fundamental fix requires the industry to converge on the same architectural change, which isn\u2019t happening anytime soon given the incentives and the fact that the major players are far from besties,\u201d he said, pointing out that Instruction-data separation would need to be baked in at the model or platform level across every major vendor. \u201cNone of them are rewarding that work commercially right now, so treat that as a multi-year research problem, not something a CISO should wait on.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Leone disagreed, arguing that a single vendor can do quite a bit, at least for its own customers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cMicrosoft has said publicly since last year that indirect prompt injection can\u2019t be fully prevented, and I give them credit for saying it out loud rather than pretending otherwise,\u201d Leone said, noting that the industry doesn\u2019t have to move in lockstep. \u201cThis attack lives inside one product,\u201d he said. \u201cIf Microsoft hardens the Copilot document path, Copilot customers get safer whether or not anyone else moves.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Dickson added that another critical problem with this vulnerability is that the carrier documents are created by legitimate employees using legitimate tools, \u201cso there\u2019s no obvious point of origin once the payload starts moving; an organization could be laundering corrupted financial figures through its own workflow for weeks before anyone notices.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Tactics that might help<\/h2>\n<p class=\"wp-block-paragraph\">That said, experts had some specific suggestions for CISOs trying to negate this problem.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">IDC\u2019s Dickson said, \u201cthe most useful lever right now sits outside the model entirely, in how much untrusted content Copilot is allowed to pull into a session without a human choosing it.\u201d He noted that enterprises can turn Copilot\u2019s auto-discovery behavior off or restrict it, and require humans to explicitly select the documents they feed it. \u201cThat alone closes off one of the two ways the attack gets a foothold,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">IDC also suggested a visible diff or redline of anything Copilot changes in a financial or otherwise consequential document, and the requirement for a human to approve the changes. \u201cThat\u2019s not a technical fix, it\u2019s a workflow one, and it\u2019s available today,\u201d Dickson said.<\/p>\n<p class=\"wp-block-paragraph\">He said that IT should also track where content came from and what was touched by an AI system, in metadata that travels with the document. \u201cIt doesn\u2019t stop the injection, but it means when something does get through, an organization can actually trace how far it spread instead of discovering a corrupted number three reports later with no way to reconstruct the chain,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">However, one expert, <a href=\"https:\/\/www.fortra.com\/profile\/tyler-reguly\" target=\"_blank\" rel=\"noopener\">Tyler Reguly<\/a>, Fortra\u2019s associate director of security R&amp;D, said that he didn\u2019t see this vulnerability having a meaningful impact because it feels like what he called a \u201claboratory vulnerability.\u201d <\/p>\n<p class=\"wp-block-paragraph\">Normal enterprise workflows don\u2019t encompass a number of the necessary steps for compromise, he said, pointing out that, if anything, people are trained not to download Word documents. Plus, he noted, looking at the blurred example in the report, the malicious document contained an additional apparently blank page which held the concealed prompts in white text.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat page is going to send up warning signs for me if someone even managed to convince me to download an external Word document,\u201d he said. So, overall, \u201cthis feels like it requires a perfect storm.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher H\u00e5kon M\u00e5l\u00f8y, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8945"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8945"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8945\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8946"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}