Word Worm Crawls into Copilot, Spreads Chaos

Håkon Måløy hid instructions in a Word document as small white text and checked whether Copilot would carry them into the next document it generated. It did: the payload altered figures in the resulting reports and copied itself onward, propagating through ordinary workflows with no way for later users to trace it back to the source. Microsoft addressed the findings twice, once via a model upgrade; neither attempt closed the vulnerability class.

Severity: Unrated · Category: Prompt Injection

Impact: Financial figures altered in generated reports · Self-propagating injection across Microsoft 365 documents

Source: The Register · Jul 29 2026 · Original source

How Fencio prevents this

The agent could not tell the difference between text it was reading and instructions it should follow. Once untrusted content reached its context window, it carried the same weight as the operator's own prompt, and the agent acted on it with every permission it had.

Fencio tags every span of context with where it came from. Instructions that arrive inside retrieved documents, tickets, emails, or tool output are treated as data, and any tool call they try to trigger is checked against the policy for untrusted content before it runs.

All incidents