July 29, 2026
The file that came from inside the office
Document-borne AI worms can self-propagate through Copilot for Word
Your Word file might secretly rewrite the next one, and commenters are fully horrified
TLDR: A researcher says a booby-trapped Word document can make Copilot change new documents and secretly pass the bad instructions along. Commenters were split between gallows humor and outrage, mostly asking why invisible text can boss around AI in the first place.
The big panic here isn’t just that Microsoft Copilot for Word can be tricked by hidden instructions inside a document — it’s that those sneaky instructions can then get copied into new documents and keep spreading. In plain English: one bad file could quietly poison the next file, then the next, all through normal office work. The researcher says this could even change important numbers, like financial figures, while hiding the attack as invisible white text. Microsoft was told in advance, but at publication there’s still no full fix, which is exactly the detail that made the comment section collectively clutch its pearls.
The community mood? A mix of dread, disbelief, and sarcastic laughter. One commenter dryly quoted the line about there being no robust fix and replied, “Well, that sounds promising..” — which pretty much became the unofficial slogan of the thread. Another summed up the whole vibe with a tiny, devastating “Oh no.” But the spiciest reactions were about the obvious question: why on earth can the AI read text that humans can’t even see? People were openly baffled that hidden text exists in Word at all, and even more baffled that Copilot appears happy to treat it like legitimate instructions. That sparked the mini-debate of the day: should invisible text be stripped out before the AI sees it, or is this just another example of AI being bolted onto software faster than anyone thought through the consequences? Either way, the crowd seems united on one point: the office document has entered its horror-movie era.
Key Points
- •The article reports a coordinated disclosure with Microsoft and MSRC concerning a self-propagating prompt injection scenario in Microsoft Copilot for Word.
- •The disclosed attack involves hidden instructions in an external document being interpreted by Copilot as part of a user request during drafting or editing.
- •According to the report, Copilot can both alter the output document and copy the hidden instructions into that new document, making it a new carrier.
- •The article frames this as an extension of Cross-Domain Prompt Injection Attacks from single interactions to propagation across trusted document workflows.
- •At publication, the article says no customer-side remediation fully addresses the issue, though exposure can be reduced through document review and treating external files as untrusted.