< Back to situations

This situation has concluded

It was preserved as a record on September 1; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 15 sources · 3 days · First seen · Last updated

Microsoft Copilot Word vulnerability

Overview

In late July 2026, security researchers disclosed a vulnerability in Microsoft 365 Copilot for Word that allows hidden, white‑on‑white prompts embedded in a document to be executed by the AI model. The payload can modify data—such as halving financial figures—and copy the hidden instructions into newly generated output, enabling the exploit to spread through standard sharing channels like Outlook, Teams, SharePoint, and OneDrive. Microsoft responded by blocking the specific proof‑of‑concept payload and issuing two mitigations, including an upgrade to the underlying GPT‑5 model, but warned that the broader class of vulnerability remains exploitable.

A few days later, researcher Håkon Måløy demonstrated a self‑propagating “worm” that leverages this indirect prompt‑injection technique. Microsoft confirmed the behavior after a 144‑day collaboration with its Security Response Center, noting that earlier mitigation attempts in April were bypassed and that a comprehensive fix is still pending. Experts continue to advise treating external documents as untrusted and employing layered security controls.

Entities

Håkon Måløy · Microsoft Word · Microsoft · Microsoft Corporation · Microsoft 365 Copilot

Timeline

  1. about 2 months ago

    [TECHNOLOGY] 8 sources
    Microsoft Copilot Word Worm Demonstrated by Security Researcher

    Security researcher Håkon Måløy showed a self‑spreading worm that exploits Microsoft 365 Copilot in Word via hidden prompt‑injection, prompting Microsoft to confirm the flaw and attempt mitigations that were at

  2. about 2 months ago

    [TECHNOLOGY] 8 sources
    Microsoft 365 Copilot Word vulnerability enables hidden‑prompt self‑propagation

    A hidden‑prompt flaw in Microsoft 365 Copilot for Word lets malicious instructions modify and copy themselves across documents, persisting despite updates; Microsoft issued mitigations but the issue remains in‑

Sources

bild.de · borncity.com · cyberinsider.com · dobreprogramy.pl · flagthis.com · infoguerra.com.br · instalki.pl · it-boltwise.de · osnews.pl · pcformat.pl · solidsoftwaretools.com · tabletowo.pl · techbook.de · telepolis.pl · thehackernews.com