A security researcher has demonstrated a worm-like attack on Microsoft Copilot for Word: invisible prompt injections hidden in documents spread automatically into new files every time they're reused. Microsoft confirmed the issue but failed to fix it after 144 days and two attempts.

Researcher says months of coordination with Microsoft have yet to produce a robust mitigation

Un prompt nascosto in Word può manipolare Copilot e replicarsi nei documenti successivi: come funziona l'attacco e come difendersi.