Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts

Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts

Posted on July 30, 2026 By CWS

Hidden commands within Microsoft Word documents can trigger unexpected behavior in Microsoft 365 Copilot, potentially altering report data and embedding the same hidden instructions in newly created documents. Security researcher Håkon Måløy revealed this vulnerability on July 28, several months after informing Microsoft about the issue.

The Vulnerability Details

Måløy’s findings indicate that the vulnerability involves Microsoft 365 Copilot misinterpreting embedded document instructions as user requests. Microsoft acknowledged the issue on March 31 and implemented two mitigations: blocking initial prompt wording and upgrading the AI model to GPT-5.5. Despite these efforts, Måløy found that modified instructions continued to work with GPT-5.6, suggesting the vulnerability remains exploitable.

The exploit requires a Copilot drafting or editing session, where the malicious document is included as an attachment or accessed from OneDrive using Microsoft’s Work IQ engine. Importantly, the attack does not rely on traditional malware execution and is not a zero-click vulnerability.

Security Implications and Recommendations

Måløy advises caution when handling external documents. He suggests treating such files as untrusted, reviewing attachments before generating or editing content, and scrutinizing Copilot outputs before further distribution. The exploit involves Copilot reading source files and mistaking hidden instructions as part of the user’s input, leading to unintended alterations and concealed prompts.

In the proof of concept, Copilot altered financial figures and embedded the full prompt in the resulting document using white, eight-point text. Word’s processing strips color and font size, making the hidden instructions visible to the AI model without user detection.

Microsoft’s Response and Future Outlook

As of now, there is no public CVE or specific Microsoft advisory addressing this issue. Microsoft employs classifiers to block high-risk prompts, but these are not universally available across all Copilot scenarios. Defender for Office 365 includes mail-flow inspection for incoming emails, and Copilot’s runtime safeguards aim to manage injected instructions. However, the effectiveness of these measures for this specific payload remains unclear.

Måløy argues that current defenses do not fully address the class of vulnerabilities due to the need for models to process potentially malicious content. Microsoft’s stance aligns, emphasizing that AI memory and prompt isolation should be managed by deterministic systems.

The ongoing nature of this vulnerability highlights the challenges in securing AI-driven applications and underscores the importance of robust safeguards as AI systems become increasingly integrated into business processes.

The Hacker News Tags:AI security, AI technology, Copilot, Cybersecurity, Document Safety, GPT-5.5, hidden prompts, Malicious Documents, Microsoft, OneDrive, Software Security, tech news, Vulnerability, Word Document, Work IQ

Post navigation

Previous Post: GitLab Resolves 13 Security Issues Affecting Data and Pipelines
Next Post: Cantina Secures $8M for Autonomous Security Innovation

Related Posts

Critical Cisco Vulnerability Added to CISA’s Exploited List Critical Cisco Vulnerability Added to CISA’s Exploited List The Hacker News
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access The Hacker News
The Hidden Weaknesses in AI SOC Tools that No One Talks About The Hidden Weaknesses in AI SOC Tools that No One Talks About The Hacker News
Russian Cyber Campaign Targets Ukraine with New Malware Russian Cyber Campaign Targets Ukraine with New Malware The Hacker News
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark