AgentsAugust 1, 2026via The Decoder
A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot
Why it matters
A demonstrated agent exploit — invisible prompt injections that propagate across documents and compromise Copilot's autonomy — exposes a critical reliability and security gap in deployed agentic systems. This is the kind of failure mode that will determine whether agents scale in enterprise.
Key signals
- Self-spreading worm embeds invisible prompt injections in Word documents
- Injections automatically propagate to new files on document reuse
- Microsoft acknowledged the vulnerability but failed to patch after 144 days
- Two patch attempts by Microsoft were unsuccessful
- Attack specifically targets Microsoft Copilot for Word — an agent-adjacent product
- Security researcher demonstrated and disclosed the issue
The hook
144 days. Microsoft still hasn't patched a self-spreading worm that hijacks Copilot through Word documents.
A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts.