type: incident · created: 2026-07-30 · updated: 2026-08-18 · tags: [cyber, digest-2026-07-31, ai-security, microsoft, copilot, prompt-injection] · confidence: not-rated · affected_sectors: [] · au_impact: false
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Summary
Security researcher Håkon Måløy disclosed that hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report and then copy the same instructions into the finished file. Microsoft confirmed the behaviour on March 31 and deployed two mitigations — blocking the original prompt wording and upgrading the underlying model to GPT-5.5 — but Måløy demonstrated the full chain still works with modified instructions on GPT-5.6. The vulnerability class remains exploitable at time of publication.
Key Details
- Date: 2026-07-30
- Source: The Hacker News
- Reliability: Tier 2/4 — Established cyber journalism
- Researcher: Håkon Måløy
- Microsoft Response: Confirmed 31 March; blocked original prompt wording; upgraded model to GPT-5.5
- Status: Still exploitable on GPT-5.6 with modified instructions
- Vulnerability Class: Prompt injection / instruction leak
Source
See Also
- Anthropic Reveals Claude Models Breached Three Organisations After Mistaking Internet for CTF
- ACSC Publishes Guidance on Secure Adoption of Agentic AI in Defence