Utopia Tech
SecurityAI-assisted1 min read

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

A security researcher disclosed a vulnerability in Microsoft 365 Copilot for Word where hidden instructions embedded in documents can manipulate AI-generated content and self-propagate into newly created files. The technique, reported to Microsoft 144 days prior to public disclosure, demonstrates how malicious prompts can persist across multiple document generation sessions, potentially compromisi

UT

Utopia Tech

July 30, 2026 · 1 min read

Share

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Måløy's

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content