This ‘fascinating’ Microsoft Excel security flaw combines spreadsheets and Copilot Agent to steal data


  • Microsoft’s latest Patch Tuesday release fixes 83 bugs
  • Including an Excel flaw that enables AI-powered zero-click data theft
  • Update is encouraged to block exfiltration via Copilot assistant

The March 2026 Patch Tuesday release from Microsoft has fixed a serious vulnerability in Excel that combines good old cross-site scripting (XSS) with indirect prompt injection for data exfiltration via Artificial Intelligence (AI).

As AI gave an old vulnerability a new twist, some security researchers described it as “fascinating” – and being a “zero-click” attack didn’t help either.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top