This “fascinating” Microsoft Excel security flaw combines spreadsheets and Copilot Agent to steal data


  • Microsoft’s latest Patch Tuesday release fixes 83 flaws
  • Including an Excel bug that enables AI-driven zero-click data theft
  • Update recommended to block exfiltration via the Copilot assistant

Microsoft’s March 2026 Patch Tuesday patched a high-severity vulnerability in Excel that combines good old cross-site scripting (XSS) with indirect prompt injection for data exfiltration via artificial intelligence (AI).

Since AI put a new spin on an old vulnerability, some security researchers have described it as “fascinating” – and the fact that it’s a “no-click” attack hasn’t helped either.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top