I would like to thank Microsoft product teams and Microsoft Security Response Center (MSRC) for collaborating with me on this technical analysis and mitigation of the disclosed vulnerabilities. The editorial opinions reflected below are solely the author’s and do not necessarily reflect those of the organizations I collaborated with.
It makes sense: with LLMs and agents based on them, even plain text becomes effectively executable, so any document can carry malicious instructions. It’s worse with complex document formats like DOCX, ODT, or PDF, since text can be hidden from the human eye and escape detection by review. Very risky tech…
It would seem so: https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588
It makes sense: with LLMs and agents based on them, even plain text becomes effectively executable, so any document can carry malicious instructions. It’s worse with complex document formats like DOCX, ODT, or PDF, since text can be hidden from the human eye and escape detection by review. Very risky tech…