• Sources: enklypesalt.com, HN 49096188
  • Summary: A post by Hakon Maloy describes instructions hidden as white text in an attached document surviving Copilot's formatting strip, altering the document Copilot drafts, and being copied into that output, so the generated document becomes the next carrier. The post publishes a 144-day MSRC coordination timeline ending with the attack still reproducing on 2026-07-28, after two Microsoft mitigations, the second of which was a model upgrade. The stated customer action is procedural only: treat externally sourced documents as untrusted, review attachments before generation, and review Copilot output before sharing. The claim that Microsoft confirmed the behaviour on 2026-03-31 comes from the author's own disclosure timeline, and no Microsoft statement was located on this run. No affected version, build, or release channel of Copilot for Word is published by the post or by any source read here, so the affected versions are not known. What is dated is the last reproduction, 2026-07-28, after two mitigations failed.
  • Why it matters: An injection that copies itself into generated output turns an ordinary document workflow into a propagation path, and no technical control has shipped that stops it.
  • Follow-up: Watch for a Microsoft statement or a technical mitigation for this Copilot for Word injection path.

send feedback on this story