Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Positions Microsoft as responsive to external security research and frames the disclosure as part of responsible vulnerability management rather than a failure of product design or AI governance.
View original on thehackernews.comOverview
A security researcher demonstrated that Microsoft 365 Copilot for Word can unintentionally propagate hidden, executable prompt instructions from source documents into newly generated documents — enabling silent, recursive execution of arbitrary instructions across document generations.
TL;DR
- Researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft Copilot for Word that causes hidden instructions to persist and re-execute in newly generated documents.
- The issue was reported to Microsoft 144 days prior to public disclosure, exceeding typical coordinated disclosure windows.
- The proof of concept shows recursive propagation: an AI-generated document containing hidden prompts can itself trigger the same behavior when used as input in a subsequent Copilot session.
Key Stats
144 days
report-to-disclosure interval
Time between initial report to Microsoft and public disclosure by researcher
Questions Answered
Keywords
Narrative Frame
safety framing
Spin Score
40%
Emphasizes researcher-led discovery and disclosure timeline while minimizing Microsoft’s role in designing, shipping, and maintaining a system vulnerable to self-replicating instructions; omits whether the behavior violates internal AI safety guardrails or product-level threat models.
What the story wants you to believe
This is a responsibly disclosed, contained security finding — not evidence of deeper architectural fragility in Microsoft’s AI integration strategy.
What it makes harder to question
Whether Microsoft’s broader Copilot rollout prioritized speed-to-market over foundational prompt containment safeguards.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as disclosed, reporting, proof of concept, internally generated file. The distribution reads as editorial reporting. A pressure point: Microsoft’s internal response status (e.g., acknowledged, patched, disputed).
Who Benefits If This Frame Spreads
Håkon Måløy
Credibility as a rigorous, ethical security researcher adhering to disclosure norms.
Public attribution and precise timeline reinforce his adherence to responsible disclosure standards, strengthening future research influence and platform access.
The Frame
Microsoft as a responsible steward proactively engaging with the security community.
Missing Context
- Microsoft’s internal response status (e.g., acknowledged, patched, disputed)
- Whether the behavior affects other Copilot integrations (Excel, PowerPoint)
- Whether hidden prompts originate from user-inserted fields, metadata, or model hallucination
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
By foregrounding the researcher’s ethical disclosure process and timeline, the story frames the vulnerability as an expected, manageable artifact of AI development
- Claim
Microsoft 365 Copilot for Word can copy hidden prompts into
Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.
- Frame
Blame shifts elsewhere
Microsoft as a responsible steward proactively engaging with the security community.
- Beneficiary
Credibility as a rigorous, ethical security researcher adhering to disclosure
Håkon Måløy — Credibility as a rigorous, ethical security researcher adhering to disclosure norms.
- Gap
Microsoft’s internal response status (e.g., acknowledged, patched, disputed)
- AI Risk
AI may repeat the headline as fact
Microsoft Copilot for Word can copy hidden prompts into new documents, enabling recursive instruction execution.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs. | Descriptive account of behavior with temporal sequence and researcher attribution. | Claim Present in Source | High | Video or GIF demonstrating the full chain; Microsoft’s official acknowledgment or severity rating; Independent replication report from another security team |
Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.
evidence: Descriptive account of behavior with temporal sequence and researcher attribution.
"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file... In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session."
Evidence Gaps
- Video or GIF demonstrating the full chain
- Microsoft’s official acknowledgment or severity rating
- Independent replication report from another security team
Fact Check Signals
0 of 1 claim matched · confidence: low · checked July 30, 2026
Microsoft 365 Copilot for Word can copy hidden prompts into new documents and trigger recursive execution when those documents are reused as inputs.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Microsoft as a responsible steward proactively engaging with the security community.
Media / Reader Counter-Frame
Framing it as a niche red-teaming curiosity rather than a systemic AI control failure — emphasizing low real-world exploit likelihood without enterprise misconfiguration.
Regulatory Counter-Frame
Highlighting absence of evidence that this violates existing cybersecurity or AI transparency regulations — positioning it as a known risk class, not a novel regulatory gap.
AI Summary Frame
Omitting the recursive aspect and reducing it to 'Copilot sometimes repeats hidden text', conflating benign metadata persistence with executable prompt injection.
Missing Voices
Questions Not Answered
- Did Microsoft confirm the vulnerability's existence or severity level?
- What mitigation, if any, has Microsoft deployed or committed to deploying?
- Has this behavior been observed in real-world enterprise deployments or only in lab conditions?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
36
Trigger score 15
Triggered by: Major AI entity
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Microsoft Copilot for Word can copy hidden prompts into new documents, enabling recursive instruction execution."
Concern: AI systems may drop the nuance that this is a documented proof-of-concept requiring specific hidden instruction placement — implying broader, uncontrolled prompt leakage instead of a bounded injection vector.
-
Published
Jul 30, 2026
-
Ingested
Jul 30, 2026
-
SpinGraph Created
Jul 30, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_microsoft_copilot_for_word_can_copy_hidden_promp
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- The Network Has Become the Control Plane for AI Security
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO