Close Menu
    What's Hot

    U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems

    As China’s A.I. Gets Stronger, It Poses New Risks to Beijing

    Attack on Egyptian Port Shows Suez Canal’s Vulnerability

    Facebook X (Twitter) Instagram
    Trending
    • U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems
    • As China’s A.I. Gets Stronger, It Poses New Risks to Beijing
    • Attack on Egyptian Port Shows Suez Canal’s Vulnerability
    • Blue Owl’s private credit fundraising falls to slowest pace in three years
    • PSI: The AI Sell-Off Missed The Companies Building The Future, Strong Buy (NYSEARCA:PSI)
    • LinkedIn Won’t Be Expanding Its Data Centers in the Next Year
    • Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
    • Japan Earthquake Death Toll Rises to 34
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

    adminBy adminJuly 30, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 30, 2026Vulnerability / AI Security

    Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

    Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

    In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.

    Måløy’s timeline says Microsoft confirmed the reported behavior on March 31 and deployed two mitigations. The first blocked the original prompt wording; the second upgraded the underlying model to GPT-5.5.

    He said the full chain worked with modified instructions on GPT-5.6 the next day, and the attack class still reproduced on July 28. “The vulnerability class therefore remains exploitable at the time of publication,” Måløy said.

    The attack is not zero-click and does not execute conventional malware. It requires a Copilot drafting or editing operation, and the malicious document must enter the model’s context as an attachment or as a OneDrive source selected by Work IQ, the intelligence engine behind Microsoft 365 Copilot.

    Cybersecurity

    The disclosure does not report exploitation in the wild, and Måløy withheld the complete payload. He recommends treating external documents as untrusted, reviewing attached documents before starting a generation or edit, and checking Copilot-generated or edited files before reuse or sharing.

    The chain runs through document text and Copilot’s own drafting behavior. Copilot reads source files to decide what belongs in a draft and can mistake instructions inside them for part of the user’s request. In the proof of concept, it halved every financial figure, copied the full prompt into the output in white, eight-point text, and disclosed neither change.

    Måløy said Word strips colour and font size before sending document text to the large language model, leaving white-on-white instructions legible to the model. One part of the payload altered the document; the other told Copilot to copy and conceal the instructions, framing those commands as source-tracking and readability requirements.

    Microsoft says Word can ground a draft on up to 20 files, emails, or meetings, and Edit with Copilot can use Work IQ. Edit with Copilot is still rolling out worldwide to users with eligible licences. In Måløy’s test, Copilot searched OneDrive for a quarterly report, found the malicious market analysis outside the folder containing the other sources, and included it. Work IQ still had to judge the file relevant.

    With the original malicious document absent and only the infected Q1 report attached, Copilot halved the figures in a Q2 draft and appended the prompt again. The new carrier was an ordinary internally generated document. The chain does not propagate on its own: each hop requires another Copilot drafting or editing operation in which the carrier enters the model’s context.

    The hidden formatting is only the entry point. Once Copilot copies the instructions into an internally generated document, the original source is no longer present when that file enters the next session. Måløy argues that this break in the provenance trail makes the manipulation harder to trace.

    Cybersecurity

    As of publication, The Hacker News found no public CVE or standalone Microsoft advisory for the Word finding in searches of NVD, CVE.org, and Microsoft’s Security Update Guide. Microsoft says jailbreak and cross-prompt injection attack (XPIA) classifiers help block high-risk prompts, although they may not be available in every Copilot scenario.

    Defender for Office 365 adds mail-flow inspection for inbound email. Microsoft describes Copilot’s runtime safeguards as covering injected instructions from grounded content. Neither Microsoft nor Måløy says whether this exact payload is detected at either layer.

    No customer-side remediation fully addresses the issue, according to Måløy. His argument is that payload-specific blocks do not reach the class: a model must process attacker-controlled content to decide whether it is malicious, so “the content being inspected participates in the act of inspection.”

    Microsoft made a related point in a June post about AI memory, writing that “Prompting alone is not a reliable security boundary” and that memory access and isolation should be controlled by deterministic systems rather than model instructions.

    Copilot copy Documents Hidden Microsoft prompts word
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleJapan Earthquake Death Toll Rises to 34
    Next Article LinkedIn Won’t Be Expanding Its Data Centers in the Next Year
    admin
    • Website

    Related Posts

    Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

    July 30, 2026

    Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

    July 30, 2026

    Apple’s Siri Got an A.I. Brain Transplant. Try These 5 Prompts to Get Acclimated.

    July 30, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems

    As China’s A.I. Gets Stronger, It Poses New Risks to Beijing

    Attack on Egyptian Port Shows Suez Canal’s Vulnerability

    Blue Owl’s private credit fundraising falls to slowest pace in three years

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by