Hakon Maloy found prompt-injection risks in Microsoft 365 Copilot Memory, Outlook, and Word. Attackers could hide commands in websites, emails, or Word documents that Copilot may read as instructions.