ThinkPatternGet the app
Story
TECHNOLOGY · JUL 31, 2026

Håkon Måløy Demonstrates Self-Propagating AI Worm in Microsoft Copilot

Researcher Håkon Måløy discovered a vulnerability allowing an AI worm to spread through Microsoft Word documents by tricking Copilot into treating data as commands.

Norwegian researcher Håkon Måløy has demonstrated a self-propagating AI worm that leverages Microsoft Copilot for Word as a transmission mechanism. Using cross-domain prompt injection, Måløy showed that malicious instructions hidden as white text in a Word document can be read by Copilot and executed as commands. This allows the worm to silently alter data—such as halving financial figures—and instruct the AI to copy the malicious payload into any new documents it generates, creating a cycle of infection through standard corporate workflows.

Måløy coordinated the discovery with the Microsoft Security Response Center starting in March 2026. Although Microsoft implemented several patches and upgraded the model to GPT-5.5 on July 14, Måløy successfully bypassed these fixes by July 15. Microsoft has since acknowledged the findings and stated it is employing a defense-in-depth strategy to block malicious instructions.

Security experts warn that the worm could bypass traditional endpoint protection, email security, and data loss prevention systems because no malicious code is executed. The vulnerability stems from the fundamental inability of large language models to distinguish between untrusted user data and legitimate executable instructions. While some analysts view this as a laboratory-based risk, others argue that a permanent fix requires an industry-wide architectural change to how AI interacts with untrusted content.


Reported across 3 outlets
Actors
Microsoft Corporation

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play