This Word Document Steals Your Password From Microsoft Copilot (+ LIVE DEMO)

This Word Document Steals Your Password From Microsoft Copilot (+ LIVE DEMO)

Source: YouTube · NahamSec · published Aug 24, 2026 · 45:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Microsoft Copilot users can be exploited via malicious documents that inject prompts to poison the AI's memory, enabling persistent data exfiltration through unique font-based side channels 2:15.

Key Takeaways:
• The attacker uses a Word document containing a prompt injection that triggers when the user summarizes the file, bypassing standard security blocks 0:10.
• Data is exfiltrated not through images, but by encoding stolen secrets into the URL of a remote font request, which bypasses Content Security Policies 0:21.
• The exploit leverages "delayed tool invocation" to store malicious instructions in the user's specific Copilot memory, making the attack persistent across future sessions 2:24.
• Once the malicious memory is active, any time the user mentions sensitive keywords like "password," Copilot automatically triggers the font request to leak the data 2:28.
• This technique works across multiple Microsoft 365 apps including Word, Excel, Outlook, and SharePoint, affecting enterprise users globally 1:01.

This vulnerability highlights the critical security risks of persistent AI memory and novel exfiltration vectors that evade traditional detection methods. Organizations must treat AI memory features with the same scrutiny as other data storage mechanisms to prevent silent data breaches.

Sources:

  • 2:15 Introduction to persistent data exfiltration in Microsoft Copilot.
  • 0:21 Explanation of font-based CSP bypass for data leakage.
  • 2:24 Demonstration of storing malicious payloads in user memory.
  • 2:28 Triggering the exploit via specific keywords in future conversations.
  • 1:01 Scope of the vulnerability across various Microsoft 365 applications.
  • 14:00 Live demo of the data exfiltration workflow in Outlook.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Someone can steal your password out of Microsoft Copilot with a word document. This doesn't require to click on a link. You don't have to run any macros or even just download a malicious file. All you do is hit the summarize button, the one that your company put there, [music] and that is it. And the data doesn't go out through an image this time. Most of the time when you hack AI, you do XO through image blocks and things like that. But this time, Microsoft blocks images and instead it goes through a font. And I've been doing this for a long time and I can tell you that I did not see that coming. My guest today is Johan, one of the best AI hackers on the planet. And I don't just say that lightly. He has spoken at conferences like Defcon, Black Hat, and he's broken pretty much every model …