🟠 High  |  Source: The Hacker News


A security researcher has demonstrated that hidden instructions embedded in a Word document can manipulate Microsoft 365 Copilot into silently altering document content — such as rewriting figures — and then propagating those same hidden instructions into any newly generated files. The attack is self-replicating across Copilot drafting sessions, meaning a single malicious document could poison multiple downstream outputs. This technique, disclosed 144 days after responsible reporting, represents a worm-like prompt injection risk within enterprise document workflows.

Security Architect’s Take: Treat AI-generated documents as untrusted inputs in your data classification and DLP policies. Until Microsoft issues a fix, consider restricting Copilot’s ability to ingest externally sourced or user-submitted Word documents in sensitive workflows, and audit any Copilot-drafted outputs for unexpected content or embedded instructions before distribution.

Original advisory: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents