AI worms? In your Copilot PC? According to this AI researcher, it's more likely than you think

13 hours ago 2

Rommie Analytics

Though I write a fair amount about AI agents, I do not use them. This is because agentic AI applications often introduce a more than medium-sized headache in terms of cybersecurity. For instance, one security research recently explained how a Word Doc could be leveraged to get Copilot to spread an AI worm.

AI researcher Håkon Måløy breaks down how the attack in a recent blog post, writing, "An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier."

The attack involves a "JSON-formatted malicious prompt." From this prompt injection of JSON-formatted data, a chain reaction wriggles into action. The worm replicating through 'carrier' documents scooped up in further Copilot-assisted workflows—the original document that kicked off the whole thing doesn't even need to be present...

Read Entire Article