Microsoft confirms an AI worm is propagating through Copilot and other MS apps
Summary
An AI worm has been confirmed by Microsoft to propagate through applications like Word and Copilot. Attackers can embed malicious instructions within documents that, when processed by Copilot, can alter figures and self-replicate into new documents, effectively spreading the worm through normal workflows.
IFF Assessment
This article describes a new type of malware (an AI worm) that can bypass existing defenses, posing a significant threat to users and organizations.
Defender Context
This discovery highlights a novel attack vector where AI models integrated into productivity suites can be exploited to propagate malware. Defenders need to be aware of how AI processing can introduce new risks and ensure users are cautious with external documents and review AI-generated content rigorously.