This blog post discusses a novel prompt injection vulnerability discovered by Håkon Måløy, which allows attackers to embed hidden instructions in Microsoft Word documents that can lead to self-replicating worms. The exploit takes advantage of Copilot for Word, where instructions can transfer and propagate through documents even if the original is not present. The issue was disclosed to Microsoft, but no comprehensive mitigation has been implemented yet.