Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could allow malicious instructions hidden within documents to alter Copilot-generated content and spread into newly created files. The issue, termed “Context Collapse, Part 3 – AI Worming through Word,” demonstrates how a document can serve as a […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
