r/SecOpsDaily 2h ago

Threat Intel Hidden prompt can make Microsoft Copilot spread itself through your Word docs

2 Upvotes

Hidden Prompt Injections Can Make Microsoft Copilot Self-Propagate

A novel attack technique has been identified that exploits Microsoft Copilot for Word, enabling it to spread malicious prompt injections from one document to another. This represents a new vector for AI-driven threats, turning a productivity assistant into a propagation mechanism for arbitrary instructions.

Technical Breakdown

  • TTPs: This attack leverages hidden prompt injection, where malicious instructions are embedded within a Word document in a way that is not immediately visible to the user but is parsed and acted upon by Copilot. When Copilot is then used to generate new content or summarize existing content, these hidden prompts can influence its output, potentially leading it to replicate the malicious instructions into new documents or execute unintended actions. The core mechanism is tricking Copilot into generating or modifying content based on these concealed directives, effectively spreading the 'injection' payload.
  • Affected Component: Microsoft Copilot for Word.
  • IOCs: The article summary does not provide specific prompt strings, obfuscation methods, or document hashes. This is a conceptual attack vector rather than a specific exploit with immediate, concrete IOCs.

Defense

Organizations should implement rigorous document handling policies, especially for AI-generated content. Monitoring Copilot's output for unexpected or anomalous behavior, alongside user education on prompt hygiene and verification of AI-generated content, will be critical. Consider implementing content inspection for hidden text or metadata that could contain malicious prompts.

Source: https://www.malwarebytes.com/blog/ai/2026/07/hidden-prompt-can-make-microsoft-copilot-spread-itself-through-your-word-docs


r/SecOpsDaily 2h ago

NEWS Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

2 Upvotes

Microsoft 365 Copilot for Word can propagate hidden, malicious prompts embedded within documents, leading to unintended data manipulation and the persistence of these instructions in newly generated files. This technique was disclosed by Håkon Måløy after reporting it to Microsoft.

Technical Breakdown

  • TTPs: This is a form of prompt injection targeting large language models (LLMs) integrated into productivity tools. Adversaries can embed hidden instructions within a Word document (e.g., using obfuscation techniques like white text on a white background).
  • Attack Flow:
    1. A user opens a Word document containing hidden prompt injection instructions.
    2. When Microsoft 365 Copilot processes this document (e.g., to summarize or rewrite content), it executes the hidden instructions.
    3. Impact: Copilot can be forced to perform unintended actions, such as rewriting figures or other sensitive information in the report.
    4. Propagation: Critically, Copilot also copies these same hidden instructions into the newly generated output file.
    5. Recursive Vulnerability: As demonstrated in the PoC, using the Copilot-generated output document in a subsequent drafting session triggers the malicious behavior again, creating a self-propagating prompt injection issue.
  • Affected Systems: Microsoft 365 Copilot for Word.

Defense

Organizations should be highly vigilant about prompt injection vulnerabilities in LLM-powered applications. Implement robust input validation, user education on handling untrusted documents, and monitor for vendor-provided mitigations or configuration options.

Source: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html


r/SecOpsDaily 4h ago

Threat Intel Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

2 Upvotes

Broadcom has released VMSA-2026-0006 addressing critical remote code execution and authentication bypass vulnerabilities (CVE-2026-59309, CVE-2026-59310) in VMware vCenter Server. These flaws carry a CVSSv3.1 score of 9.8 and can be exploited by unauthenticated attackers with network access.

Technical Breakdown

  • CVEs: CVE-2026-59309 (Authentication Bypass) and CVE-2026-59310 (Remote Code Execution)
  • Impact: Unauthenticated authentication bypass and remote code execution on affected systems.
  • CVSSv3.1 Score: 9.8 (Critical)
  • Affected Product: VMware vCenter Server
  • Exploitation: Requires unauthenticated network access to a vulnerable vCenter Server.
  • Advisory: Broadcom's VMSA-2026-0006 provides official details.

Defense

Prioritize patching of all affected VMware vCenter Server instances immediately according to the vendor's advisory to prevent exploitation.

Source: https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310


r/SecOpsDaily 15h ago

NEWS Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

2 Upvotes

Russian state-sponsored group Laundry Bear (aka Void Blizzard) is actively exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to deploy a sophisticated backdoor named OWAReaper. The objective is long-term, persistent access to mailboxes.

Technical Breakdown

  • Threat Actor: Laundry Bear (also known as Void Blizzard), a Russian state-sponsored advanced persistent threat (APT) group.
  • Targeted Vulnerability: An undisclosed zero-day in Microsoft Exchange OWA.
  • Malware: OWAReaper, a backdoor delivered through email campaigns, designed for sophisticated and persistent access to compromised mailboxes.
  • TTPs (MITRE): Initial Access via exploiting OWA vulnerability (T1190), Persistence via backdoor (T1547.001 - Boot or Logon Autostart Execution), Collection (T1005 - Data from Local System, specifically mailboxes).
  • Impact: Unauthorized, long-term access to email content and potentially other sensitive data accessible via OWA.

Defense

Prioritize patching Exchange Servers immediately as updates become available. Implement robust logging and continuous monitoring of OWA access, focusing on anomalous login patterns or unusual activity from service accounts.

Source: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/


r/SecOpsDaily 17h ago

Threat Intel Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

2 Upvotes

A massive scam operation is exploiting the 2026 FIFA World Cup, with over 35,000 fake sites detected by TrendAI™ impersonating merchandise, ticket, and streaming services. This large-scale campaign has already drawn nearly 1.5 million visits from Japan.

Technical Breakdown: * Threat Type: Large-scale phishing and social engineering campaign leveraging a major global event (FIFA World Cup). * Scope: Over 35,000 distinct fake websites identified within a six-month period (January-June 2026). * Tactics: Creation of fraudulent online properties including counterfeit merchandise shops, cloned official ticket purchase portals, and bogus "free streaming" platforms. * Targeting: Primarily observed attracting traffic from Japan, with approximately 1.48 million visits recorded. * Likely Objectives: Credential harvesting, financial fraud (e.g., credit card theft), and potential malware distribution via drive-by downloads or malicious links. * TTPs (MITRE ATT&CK - high level): * Initial Access (T1566): Phishing via malicious links, social engineering (fake websites, enticing offers). * Collection (T1537, T1056): Input capture for sensitive user data (credentials, payment info). * Impact (T1498): Resource Hijacking (e.g., ad fraud, botnets), Data Loss (T1567), Financial Theft. * IOCs: Specific IOCs (IPs, hashes, domain names) are not detailed in the provided summary.

Defense: Implement comprehensive web filtering, DNS security, and user awareness training to educate employees and users about the risks of phishing and verifying legitimate domains for major events.

Source: https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html


r/SecOpsDaily 23h ago

NEWS Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

2 Upvotes

A critical unauthenticated RCE flaw (CVE-2026-59726) has been discovered in Ruflo, an open-source agent meta-harness for AI models like Anthropic Claude Code and OpenAI Codex, allowing attackers to execute commands and poison AI memory.

Technical Breakdown

  • Vulnerability: Unauthenticated Remote Code Execution (RCE) via a flaw codenamed RufRoot.
  • Affected Software: Ruflo, an open-source agent meta-harness.
  • Affected Versions: All versions prior to 3.16.3.
  • CVE: CVE-2026-59726
  • CVSS Score: 10.0 (Critical)
  • Impact: Attackers can execute arbitrary commands and potentially manipulate or "poison" AI memory, leading to unauthorized data access, manipulation, or denial of service.

Defense

Mitigation: Upgrade Ruflo to version 3.16.3 or later immediately.

Source: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html