// Microsoft 365HIGH
Security researcher Håkon Måløy disclosed a cross-domain prompt injection vulnerability in Microsoft Copilot for Word that allows hidden malicious instructions embedded in documents to alter Copilot-generated content and propagate to newly created files. The flaw enables self-replicating AI worms through standard enterprise document workflows across SharePoint, Teams, Outlook, and OneDrive. Following a 144-day coordinated disclosure starting March 6, 2026, Microsoft deployed mitigations including model upgrades, but modified payloads continued to reproduce the attack through July 28, 2026, indicating the architectural issue remains partially unresolved.
- Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Prop(opens in a new tab)
- Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into S(opens in a new tab)
- Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cis(opens in a new tab)
// Get alerts for Microsoft 365