Overview On July 28, 2026, security researcher Håkon Måløy publicly disclosed a new attack technique called "AI Worming through Word". The attack exploits a hint injection vulnerability in Microsoft Copilot for Word, allowing malicious instructions to self-replicate and spread in normal document workflows, forming a new type of document-based AI...
