Researchers identified a self-replicating prompt injection attack that allows AI agents in Microsoft Word to spread hidden instructions. The attack turns documents into carriers, enabling the instructions to propagate automatically across future AI-assisted workflows.