Return to Threats

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

thehackernews.com 2026-07-30 prompt injection Critical

What Happened

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Måløy's

Why It Matters

The report describes a Microsoft Copilot for Word technique where hidden instructions in a document can be read by Copilot, then copied into a newly generated file, allowing the behavior to propagate through normal document workflows. Microsoft has described this broader pattern as indirect prompt injection, where hidden instructions inside content are treated as trusted input. RealGround relevance: this is a high-priority prompt-injection and data-governance risk for Copilot deployments, especially where agents can process internal documents and reuse generated outputs across workflows.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to prompt injection. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

Talk to AI CISO