AgentsAugust 1, 2026via The Decoder

A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot

Why it matters

A demonstrated agent exploit — invisible prompt injections that propagate across documents and compromise Copilot's autonomy — exposes a critical reliability and security gap in deployed agentic systems. This is the kind of failure mode that will determine whether agents scale in enterprise.

Key signals

  • Self-spreading worm embeds invisible prompt injections in Word documents
  • Injections automatically propagate to new files on document reuse
  • Microsoft acknowledged the vulnerability but failed to patch after 144 days
  • Two patch attempts by Microsoft were unsuccessful
  • Attack specifically targets Microsoft Copilot for Word — an agent-adjacent product
  • Security researcher demonstrated and disclosed the issue

The hook

144 days. Microsoft still hasn't patched a self-spreading worm that hijacks Copilot through Word documents.

A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts.

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.