This ‘fascinating’ Microsoft Excel security flaw combines spreadsheets and Copilot Agent to steal data



  • Microsoft’s latest Patch Tuesday release fixes 83 bugs
  • Including an Excel bug that allows AI-powered no-click data theft
  • Update urged to block exfiltration via Copilot assistant

Microsoft’s March 2026 Patch Tuesday release fixed a high-severity vulnerability in Excel, which combines old cross-site scripting (XSS) with indirect fast injection for data exfiltration via Artificial Intelligence (AI).

Since AI put a new spin on an old vulnerability, some security researchers described it as “fascinating,” and the fact that it was a “zero-click” attack didn’t help matters either.



Leave a Comment

Your email address will not be published. Required fields are marked *