Context Collapse, Part 3 - AI Worming through Word
Summary
The post documents a coordinated disclosure with Microsoft about a Copilot for Word vulnerability that allows attacker-controlled instructions embedded in documents to influence and propagate through downstream files. It describes a two-stage attack: instructions in an initial document alter content and copy themselves into new documents, enabling self-propagation. The piece discusses mitigations, partial fixes, and the broader implications for security in AI-assisted document workflows.