A security researcher has created a self-replicating attack that can spread through Microsoft Word documents and compromise Microsoft Copilot functionality. The attack involves hiding malicious code within documents, which is then automatically injected into new files when they are reused. Microsoft has acknowledged the issue but has yet to implement a fix, despite attempts over a four-month period. This vulnerability highlights the potential risks associated with AI-powered tools and the importance of addressing security concerns in a timely manner.