Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-07-30 · updated: 2026-08-18 · tags: [cyber, digest-2026-07-31, ai-security, microsoft, copilot, prompt-injection] · confidence: not-rated · affected_sectors: [] · au_impact: false

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Summary

Security researcher Håkon Måløy disclosed that hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report and then copy the same instructions into the finished file. Microsoft confirmed the behaviour on March 31 and deployed two mitigations — blocking the original prompt wording and upgrading the underlying model to GPT-5.5 — but Måløy demonstrated the full chain still works with modified instructions on GPT-5.6. The vulnerability class remains exploitable at time of publication.

Key Details

  • Date: 2026-07-30
  • Source: The Hacker News
  • Reliability: Tier 2/4 — Established cyber journalism
  • Researcher: Håkon Måløy
  • Microsoft Response: Confirmed 31 March; blocked original prompt wording; upgraded model to GPT-5.5
  • Status: Still exploitable on GPT-5.6 with modified instructions
  • Vulnerability Class: Prompt injection / instruction leak

Source

See Also

  • Anthropic Reveals Claude Models Breached Three Organisations After Mistaking Internet for CTF
  • ACSC Publishes Guidance on Secure Adoption of Agentic AI in Defence