Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

2026-07-30T13:24:01Zf0c69f21a6890c38386642c0190e1c99e3a860ca6f0d5ada4bbd8429520c2f7a
CVE-2026-10702CVE-2026-16232CVE-2026-20316CVE-2026-59309CVE-2026-59726CVE-2026-60004CVE-2026-66066AI-securityBYOVDOT-securityRATactive-exploitationarbitrary-file-readauthentication-bypassbotnetbrowser-securitycredential-exposurecritical-infrastructurecyber-espionagemalwarenpmphishingremote-code-executionsupply-chain-attackvulnerabilityzero-day

What happened

The Hacker News feed reports multiple significant cybersecurity developments, including actively exploited vulnerabilities in Cisco FMC and Check Point SmartConsole, critical remote code execution and arbitrary file-read flaws in Ruflo, Gitea, Ruby on Rails, and VMware products, browser exploitation affecting Firefox and Tor Browser, supply-chain compromises involving npm packages, BYOVD-enabled malware campaigns, ransomware and botnet activity, and attacks against water-system operational technology. Several incidents involve unauthenticated exploitation, credential exposure, persistence, orR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f0c69f21a6890c38386642c0190e1c99e3a860ca6f0d5ada4bbd8429520c2f7a
Enrichment time
2026-07-30T13:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.