A security researcher has demonstrated a worm-like attack targeting Microsoft Copilot for Word, which spreads automatically through invisible prompt injections embedded within documents, according to The Decoder.
The vulnerability allows the malicious code to propagate without user awareness. Microsoft acknowledged the issue but, as reported by The Decoder, has not successfully resolved it even after 144 days and two attempts at fixing the problem.
This security gap raises concerns for Japanese enterprises relying on AI-assisted tools like Microsoft Copilot, highlighting the need for robust safeguards in AI integrations amid growing digital transformation efforts in Japan’s financial and technology sectors.
