{"id":124764,"date":"2026-07-30T19:33:13","date_gmt":"2026-07-30T19:33:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/124764\/"},"modified":"2026-07-30T19:33:13","modified_gmt":"2026-07-30T19:33:13","slug":"researcher-shows-hidden-word-prompts-can-spread-through-microsoft-copilot-altering-data-biggo-finance","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/124764\/","title":{"rendered":"Researcher Shows Hidden Word Prompts Can Spread Through Microsoft Copilot, Altering Data \u2014 BigGo Finance"},"content":{"rendered":"<p>A security researcher has demonstrated that hidden instructions planted inside a Microsoft Word document can force Microsoft 365 Copilot to secretly manipulate financial data and then copy the same malicious commands into newly generated files, creating a self-propagating chain that survives model upgrades and remains exploitable.<\/p>\n<p>H\u00e5kon M\u00e5l\u00f8y, a Norwegian data scientist, published the findings on July 28 after a 144-day coordinated disclosure period with Microsoft. The technique does not require malware or a zero-click exploit. It abuses the way Copilot reads source files while drafting or editing, treating invisible text as legitimate instructions and embedding those instructions into its output without alerting the user.<\/p>\n<p>In a proof-of-concept scenario, an employee downloads a market analysis from a compromised website and attaches it while preparing a quarterly report in Copilot. The document contains instructions formatted as white, eight-point text. Word strips color and font size before sending text to the large language model, leaving the white-on-white payload fully legible to the AI. Copilot then halves every financial figure in the draft, copies the full prompt into the output in the same hidden formatting, and discloses neither action to the user.<\/p>\n<p>The newly generated file becomes a carrier. When a second employee later uses that internal report as source material for another Copilot session, the cycle repeats. The original malicious document is no longer needed, and the attack can continue without further involvement from the compromised website or the attacker, according to M\u00e5l\u00f8y. He described the chain as one of the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite.<\/p>\n<p>M\u00e5l\u00f8y reported the issue to Microsoft in March 2026. The company confirmed the behavior on March 31 and deployed two mitigations: a block on the original prompt wording and an upgrade of the underlying model to GPT-5.5. The following day, M\u00e5l\u00f8y reworded the payload and successfully executed the full chain on GPT-5.6. As of July 28, the vulnerability class still reproduced, he said.<\/p>\n<p>The attack is not automatic. It requires a Copilot drafting or editing operation, and the malicious document must enter the model&#8217;s context as an attachment or as a OneDrive source selected by Work IQ, the intelligence engine behind Microsoft 365 Copilot. In M\u00e5l\u00f8y&#8217;s test, Copilot searched OneDrive for a quarterly report, found the malicious market analysis outside the folder containing the other sources, and included it after Work IQ judged the file relevant.<\/p>\n<p>With the original malicious document absent and only the infected Q1 report attached, Copilot halved the figures in a Q2 draft and appended the prompt again. The new carrier was an ordinary internally generated document. The chain does not propagate on its own; each hop requires another Copilot drafting or editing operation in which the carrier enters the model&#8217;s context.<\/p>\n<p>M\u00e5l\u00f8y argues that the hidden formatting is only the entry point. Once Copilot copies the instructions into an internally generated document, the original source is no longer present when that file enters the next session. This break in the provenance trail makes the manipulation harder to trace.<\/p>\n<p>As of publication, no public CVE or standalone Microsoft advisory for the Word finding appeared in searches of the National Vulnerability Database, CVE.org, or Microsoft&#8217;s Security Update Guide. Microsoft says jailbreak and cross-prompt injection attack classifiers help block high-risk prompts, although they may not be available in every Copilot scenario. Defender for Office 365 adds mail-flow inspection for inbound email. Neither Microsoft nor M\u00e5l\u00f8y has confirmed whether this exact payload is detected at either layer.<\/p>\n<p>M\u00e5l\u00f8y contends that payload-specific blocks do not address the broader vulnerability class. A model must process attacker-controlled content to decide whether it is malicious, meaning the content being inspected participates in the act of inspection. He likened relying on the model to detect such attacks to asking an interpreter to execute an untrusted program to determine whether that program is safe to execute.<\/p>\n<p>Microsoft made a related argument in a June post about AI memory, writing that prompting alone is not a reliable security boundary and that memory access and isolation should be controlled by deterministic systems rather than model instructions. M\u00e5l\u00f8y said the long-term challenge lies in designing systems in which goals and intentions exist independently of the information being processed. Until then, any system that integrates a large language model into a trusted workflow must assume that attacker-controlled content entering the model&#8217;s context will result in compromise at some rate.<\/p>\n<p>No customer-side remediation fully addresses the issue, according to M\u00e5l\u00f8y. He recommends treating externally sourced documents as untrusted when using them in Copilot, fully reviewing attached documents before starting a generation or edit, and checking Copilot-generated or edited files before reuse or sharing.<\/p>\n","protected":false},"excerpt":{"rendered":"A security researcher has demonstrated that hidden instructions planted inside a Microsoft Word document can force Microsoft 365&hellip;\n","protected":false},"author":2,"featured_media":124765,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,34352,9564,62746,320,8172,7852,62747,33867,10945,11609],"class_list":["post-124764","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-gpt-5-6","tag-gpt-5-5","tag-hakon-maloy","tag-microsoft","tag-microsoft-365-copilot","tag-microsoft-copilot","tag-microsoft-defender-for-office-365","tag-onedrive","tag-word","tag-work-iq"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=124764"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124764\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/124765"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=124764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=124764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=124764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}